Junglewise Threat Intelligence

CVE-2026-92425: Hydra Booking insecure direct object reference in host management

CVE-2026-92425 · Severity: medium · CVSS 5.5 · Published 2026-09-19

Executive brief

The Hydra Booking WordPress plugin for appointment scheduling contains an access control flaw that allows privileged users with a custom admin role to view, edit, and delete other hosts' booking records and associated WordPress accounts without proper authorization checks. An attacker with this role can tamper with or remove competitors' data and user accounts through the plugin's administrative functions.

Technical details

The plugin fails to enforce object-level authorization checks on host-management operations, allowing authenticated users with the custom administrator role to perform IDOR attacks on other hosts' records and linked WordPress accounts. The vulnerability requires the attacker to hold the plugin's own administrator-assigned custom role and conduct operations via API or interface tampering. This is classified as Broken Access Control (CWE-639) and is remotely exploitable by authorized users.

Affected products

  • WP Desk Hydra Booking before 1.2.4

Timeline

  • 2026-09-19: disclosed: Security advisory published
  • 2026-09-19: patched: Version 1.2.4 released with fix

References