Unauthorized Booking Cancellation Vulnerability in Hydra Booking Plugin for WordPress
CVE-2025-12787

5.3MEDIUM

What is CVE-2025-12787?

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is susceptible to unauthorized cancellation of bookings in all versions including and prior to 1.1.27. This vulnerability arises from the plugin's reliance on a predictably generated token for booking cancellations, coupled with a universally shared nonce across sessions. As a result, unauthenticated attackers can exploit this weakness to target the tfhb_meeting_form_cancel AJAX endpoint, enabling them to cancel bookings at will through brute force methods.

Affected Version(s)

Hydra Booking — Appointment Scheduling & Booking Calendar * <= 1.1.27

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ahmad Salem
.
CVE-2025-12787 : Unauthorized Booking Cancellation Vulnerability in Hydra Booking Plugin for WordPress