Privilege Escalation Vulnerability in Hydra Booking Plugin for WordPress
CVE-2025-7689
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 July 2025
What is CVE-2025-7689?
The Hydra Booking plugin for WordPress suffers from a Privilege Escalation vulnerability due to inadequate capability checks in the tfhb_reset_password_callback() function. This flaw allows authenticated users with Subscriber-level access or higher to resetAdministrator passwords, leading to potential unauthorized access and full administrative control. Patch your plugin to secure your WordPress site.
Affected Version(s)
Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings 1.1.0 <= 1.1.18