Weak configuration vulnerability in Hydra Booking — Appointment Scheduling & Booking Calendar 1.1.27

The Hydra Booking plugin for WordPress allows users to schedule and book appointments. However, there is a security vulnerability in all versions up to 1.1.27 that allows unauthorized cancellation of bookings. This is because the plugin’s function for submitting meeting forms uses weak values to create cancellation tokens, which are shared globally. This means that someone without proper authorization could potentially cancel any booking by using brute force attacks on the plugin’s AJAX endpoint.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.