WordPress Plugin Vulnerabilities
Hydra Booking 1.1.0 - < 1.2.3 - Hydra Host+ Host Profile Takeover via IDOR
Description
The plugin does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a plugin-assigned host role to modify other hosts' profile data and reassign ownership of another host's record to themselves.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
IDOR
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Ossacip Thanh
Submitter
Ossacip Thanh
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-17 (about 2 days ago)
Added
2026-09-17 (about 1 day ago)
Last Updated
2026-09-17 (about 1 day ago)