Themefic Hydra Booking Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in the Themefic Hydra Booking WordPress plugin, affecting versions through 1.1.32. This vulnerability allows low-privileged users to escalate their privileges, potentially leading to full control of the website.

Impact

Exploitation of this vulnerability could allow a user to gain higher privileges, enabling them to take full control of the website.

Remediation

Users of the Themefic Hydra Booking WordPress plugin should update to version 1.1.33 or later. Patchstack users can activate auto-update for vulnerable plugins.

Added: Jan 22, 2026, 5:45 PM
Updated: Jan 22, 2026, 5:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
2.3
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.