The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on the same site.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 19 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on the same site. | |
| Title | Hydra Booking < 1.2.2 - Hydra Host+ Cross-Host Booking Deletion and Modification via IDOR | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-19T06:00:18.070Z
Reserved: 2026-09-16T09:54:24.333Z
Link: CVE-2026-92420
No data.
Status : Received
Published: 2026-09-19T07:16:33.893
Modified: 2026-09-19T07:16:33.893
Link: CVE-2026-92420
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.