SQL Injection Vulnerability in Themefic Hydra Booking Plugin
CVE-2025-49323

8.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 June 2025

What is CVE-2025-49323?

The Themefic Hydra Booking plugin for WordPress is susceptible to an SQL Injection vulnerability that allows attackers to manipulate SQL queries. This weakness can lead to unauthorized access to sensitive data or compromise the database. Users of Hydra Booking versions up to 1.1.10 should take immediate action to secure their sites against this threat.

Affected Version(s)

Hydra Booking <= 1.1.10

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ngoc Quang Bach (maysbachs) (Patchstack Alliance)
.