Executive brief
Themefic Hydra Booking, a WordPress plugin used for managing reservations and appointments, contains a security flaw that fails to properly verify user permissions. This allows unauthorized individuals to perform actions or access data that should be restricted to administrators. An exploit could lead to unauthorized changes to booking records, exposure of customer information, or disruption of the reservation service.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Themefic Hydra Booking plugin for WordPress through version 1.1.41. The flaw stems from incorrectly configured access control security levels, where sensitive functions fail to validate the authorization or authentication status of the requester. An unauthenticated remote attacker can exploit this by sending crafted network requests to trigger these functions, potentially leading to unauthorized data modification or disclosure. The issue is resolved in version 1.1.42.
Affected products
- Themefic Hydra Booking n/a through 1.1.41
Timeline
- 2026-04-15: other: Reported by researcher raihan adi arba
- 2026-05-15: advisory: Patchstack advisory published
- 2026-06-01: disclosed: NVD publication date