WordPress Plugin Vulnerabilities

Hydra Booking < 1.2.4 - Hydra Host+ Cross-Host Account Modification and Deletion via IDOR

Description

The plugin does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-assigned custom role to read, modify and permanently delete other hosts' records and the WordPress user accounts linked to them.

Proof of Concept

Affects Plugins

Fixed in 1.2.4

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Stefan Spasic
Submitter
Stefan Spasic
Verified
Yes

Timeline

Publicly Published
2026-09-17 (about 2 days ago)
Added
2026-09-17 (about 1 day ago)
Last Updated
2026-09-17 (about 1 day ago)

Other