Unauthorized Profile Modification in Hydra Booking - Appointment Scheduling & Booking Calendar Plugin
CVE-2026-92421

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 September 2026

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-92421?

The Hydra Booking - Appointment Scheduling & Booking Calendar plugin for WordPress versions prior to 1.2.3 is susceptible to an authorization bypass vulnerability. This flaw allows authenticated users with the host role to modify other hosts' profile information and transfer ownership of related records without proper verification. The plugin fails to ensure that the host record being altered correlates to the user making the request, which opens the door to unauthorized data manipulation and privacy breaches.

Affected Version(s)

Hydra Booking β€” Appointment Scheduling & Booking Calendar 1.1.0 < 1.2.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ossacip Thanh
WPScan
.