Hydra Booking WordPress Plugin Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress, affecting versions through 1.2.1. The vulnerability exists in the '/wp-json/hydra-booking/v1/booking/details/{id}' REST endpoint. The issue arises because the 'getBookingDetails()' callback only checks for the 'tfhb_manage_options' capability, without verifying if the requested booking belongs to the authenticated host. This flaw enables authenticated attackers with Hydra Host-level access to access sensitive booking information from other hosts, including attendee details and payment information, by manipulating booking IDs.

Impact

Exploitation of this vulnerability allows authenticated users with the appropriate permissions to access and view sensitive booking information that belongs to other hosts.

Reproduction

To reproduce this vulnerability, an authenticated user with Hydra Host-level access can send a request to the '/wp-json/hydra-booking/v1/booking/details/{id}' endpoint, where '{id}' is the ID of a booking that does not belong to the user's host. The response will include sensitive details from the booking, such as attendee names, emails, phone numbers, addresses, meeting information, payment status, transaction history, and internal notes.

Remediation

Users are advised to update the Hydra Booking WordPress plugin to version 1.1.44 or later, where this vulnerability has been addressed.

Added: Jul 9, 2026, 10:30 AM
Updated: Jul 9, 2026, 10:30 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.3
remediation
0.0
relevance
9.2
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.