CVE-2026-92420: Unknown Hydra Booking — Appointment Scheduling & Booking Calendar

Low severity, CVSS 3.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on the same site.

Affected products

  • Unknown Hydra Booking — Appointment Scheduling & Booking Calendar: before 1.2.2 (fixed in 1.2.2)

Published 2026-09-19. Last modified 2026-09-21.