Stored Cross-Site Scripting Vulnerability in Hydra Booking Plugin by WordPress
CVE-2026-15948
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 August 2026
What is CVE-2026-15948?
The Hydra Booking plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input validation and output encoding on the 'first_name' parameter. This vulnerability permits authenticated users with host-level access to inject malicious scripts that execute whenever a victim accesses a compromised page. Furthermore, the tfhb_host role can be self-assigned by any visitor using the plugin's public Signup shortcode, potentially enabling unauthenticated users to exploit this security flaw.
Affected Version(s)
Hydra Booking β Appointment Scheduling & Booking Calendar 0 <= 1.2.2