Junglewise Threat Intelligence

CVE-2026-92421: Hydra Booking host profile takeover via insecure direct object reference

CVE-2026-92421 · Severity: medium · CVSS 4.7 · Published 2026-09-19

Executive brief

The Hydra Booking WordPress plugin used for appointment scheduling does not properly verify that authenticated users can only modify their own host profile data. An authenticated host user can take over other hosts' profiles and reassign ownership of those records to themselves, gaining unauthorized access to scheduling and booking functionality for other service providers.

Technical details

An insecure direct object reference (IDOR) vulnerability in the plugin allows authenticated users with the host role to modify host records without authorization checks. An attacker with valid plugin credentials can manipulate requests to access and modify arbitrary host profile data. The vulnerability is fixed in version 1.2.3.

Affected products

  • Hydra Booking Hydra Booking 1.1.0 to before 1.2.3

Timeline

  • 2026-09-17: disclosed: Publicly disclosed on WPScan
  • 2026-09-19: patched: Fixed in version 1.2.3

References