WordPress Plugin Vulnerabilities

Hydra Booking < 1.1.28 - Unauthenticated Payment Bypass

Description

The plugin is vulnerable to missing payment verification to unauthenticated payment bypass due to the plugin accepting client-controlled payment confirmation data in the tfhb_meeting_paypal_payment_confirmation_callback function without server-side verification with PayPal's API. This makes it possible for unauthenticated attackers to bypass payment requirements and confirm bookings as paid without any actual payment transaction occurring.

Affects Plugins

Fixed in 1.1.28

References

Miscellaneous

Original Researcher
Ahmad Salem (a7mad.cc)
Verified
No

Timeline

Publicly Published
2025-11-10 (about 8 months ago)
Added
2025-11-11 (about 8 months ago)
Last Updated
2025-11-11 (about 8 months ago)

Other