WordPress Plugin Vulnerabilities
Hydra Booking < 1.1.28 - Unauthenticated Payment Bypass
Description
The plugin is vulnerable to missing payment verification to unauthenticated payment bypass due to the plugin accepting client-controlled payment confirmation data in the tfhb_meeting_paypal_payment_confirmation_callback function without server-side verification with PayPal's API. This makes it possible for unauthenticated attackers to bypass payment requirements and confirm bookings as paid without any actual payment transaction occurring.
Affects Plugins
References
Miscellaneous
Original Researcher
Ahmad Salem (a7mad.cc)
Verified
No
WPVDB ID
Timeline
Publicly Published
2025-11-10 (about 8 months ago)
Added
2025-11-11 (about 8 months ago)
Last Updated
2025-11-11 (about 8 months ago)