PT-2025-31186 · WordPress · Hydra Booking
Kenneth Dunn
·
Published
2025-07-29
·
Updated
2025-08-03
·
CVE-2025-7689
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hydra Booking plugin for WordPress versions 1.1.0 through 1.1.18
Description
The Hydra Booking plugin for WordPress is susceptible to privilege escalation. A missing capability check within the
tfhb reset password callback() function allows authenticated attackers with Subscriber-level access or higher to reset the password of an Administrator user, resulting in full administrative control.Recommendations
Hydra Booking plugin for WordPress version 1.1.0 through 1.1.18: Update the plugin to a version where the capability check is implemented.
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hydra Booking