Junglewise Threat Intelligence

CVE-2026-57388: Themefic Hydra Booking Stored XSS

CVE-2026-57388 · Severity: high · CVSS 7.1 · Published 2026-07-13

Technologies: Themefic Hydra Booking. Vendors: Themefic.

Executive brief

Themefic Hydra Booking, a WordPress plugin used for managing reservations and bookings, contains a security flaw that allows attackers to inject malicious scripts into the website. If an administrator or visitor views a page containing this injected content, the script can execute in their browser, potentially leading to unauthorized actions, data theft, or redirection to malicious sites. This vulnerability can be exploited remotely without needing a password, though it requires a user to interact with a malicious link or page.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Themefic Hydra Booking plugin for WordPress (versions up to and including 1.1.44). The flaw stems from improper neutralization of user-supplied input during web page generation, allowing unauthenticated attackers to inject arbitrary web scripts. While the attack is unauthenticated, successful exploitation requires user interaction, such as a privileged user visiting a crafted page where the malicious payload is stored. Once executed, the script runs within the context of the victim's session, which can lead to session hijacking or unauthorized administrative actions. The issue is resolved in version 1.1.45.

Affected products

  • Themefic Hydra Booking <= 1.1.44

Timeline

  • 2026-05-19: other: Reported by researcher HaiND
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: CVE published to NVD dataset
  • 2026-07-13: patched: Version 1.1.45 released to address the vulnerability

References

Related threats