Hydra Booking
Hydra Booking: vulnerabilidades y CVE
Hydra Booking tiene 9 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses8
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-92425 | Media (5.5) | 0.31% | — | 19 sept 2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its… |
| CVE-2026-92421 | Media (4.7) | 0.29% | — | 19 sept 2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users… |
| CVE-2026-92420 | Baja (3.8) | 0.32% | — | 19 sept 2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints,… |
| CVE-2026-15948 | Media (6.4) | 0.36% | — | 15 ago 2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 1.2.2 due to… |
| CVE-2026-28188 | Alta (7.3) | 0.30% | — | 13 ago 2026 | Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions. |
| CVE-2026-12433 | Media (4.3) | 0.45% | — | 9 jul 2026 | The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.2.1 via the… |
| CVE-2025-12788 | Media (5.3) | 0.33% | — | 11 nov 2025 | The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment verification to unauthenticated payment bypass in all versions up to, and including, 1.1.27. This is… |
| CVE-2025-12787 | Media (5.3) | 0.29% | — | 11 nov 2025 | The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking cancellation in all versions up to, and including, 1.1.27. This is due to the plugin's… |
| CVE-2025-7689 | Alta (8.8) | 0.37% | — | 29 jul 2025 | The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tfhb_reset_password_callback() function in versions 1.1.0 to 1.1.18. This makes it possible for… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.