« Volver al listado

Hydra Booking

Hydra Booking: vulnerabilidades y CVE

Hydra Booking tiene 9 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses8
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-92425Media (5.5)0.31%—19 sept 2026
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its…
CVE-2026-92421Media (4.7)0.29%—19 sept 2026
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users…
CVE-2026-92420Baja (3.8)0.32%—19 sept 2026
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints,…
CVE-2026-15948Media (6.4)0.36%—15 ago 2026
The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 1.2.2 due to…
CVE-2026-28188Alta (7.3)0.30%—13 ago 2026
Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.
CVE-2026-12433Media (4.3)0.45%—9 jul 2026
The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.2.1 via the…
CVE-2025-12788Media (5.3)0.33%—11 nov 2025
The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment verification to unauthenticated payment bypass in all versions up to, and including, 1.1.27. This is…
CVE-2025-12787Media (5.3)0.29%—11 nov 2025
The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking cancellation in all versions up to, and including, 1.1.27. This is due to the plugin's…
CVE-2025-7689Alta (8.8)0.37%—29 jul 2025
The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tfhb_reset_password_callback() function in versions 1.1.0 to 1.1.18. This makes it possible for…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services4
  2. T1068 Exploitation for Privilege Escalation1
  3. T1078 Valid Accounts1
  4. T1098 Account Manipulation1
  5. T1098.002 Additional Email Delegate Permissions1
  6. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.