Stored Cross-Site Scripting Vulnerability in Hydra Booking Plugin by WordPress
CVE-2026-15948

6.4MEDIUM

What is CVE-2026-15948?

The Hydra Booking plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input validation and output encoding on the 'first_name' parameter. This vulnerability permits authenticated users with host-level access to inject malicious scripts that execute whenever a victim accesses a compromised page. Furthermore, the tfhb_host role can be self-assigned by any visitor using the plugin's public Signup shortcode, potentially enabling unauthenticated users to exploit this security flaw.

Affected Version(s)

Hydra Booking β€” Appointment Scheduling & Booking Calendar 0 <= 1.2.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.