SQL Injection Vulnerability in Themefic Hydra Booking Plugin
CVE-2025-49323
8.5HIGH
What is CVE-2025-49323?
The Themefic Hydra Booking plugin for WordPress is susceptible to an SQL Injection vulnerability that allows attackers to manipulate SQL queries. This weakness can lead to unauthorized access to sensitive data or compromise the database. Users of Hydra Booking versions up to 1.1.10 should take immediate action to secure their sites against this threat.
Affected Version(s)
Hydra Booking <= 1.1.10
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Ngoc Quang Bach (maysbachs) (Patchstack Alliance)