Missing Authorization
4 records33.3%First: 2025. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 12 vulnerability records associated with Hydra Booking — Appointment Scheduling & Booking Calendar, published between 2025 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
Use this history
A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.
| Year | Records | Relative volume |
|---|---|---|
| 2025 | 7 | |
| 2026 | 5 |
| Severity | Records | Share |
|---|---|---|
| Critical | 1 | 8.3% |
| High | 2 | 16.7% |
| Medium | 9 | 75% |
First: 2025. Latest: 2026.
First: 2025. Latest: 2025.
First: 2025. Latest: 2025.
First: 2026. Latest: 2026.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
1.2.21.1.451.1.421.1.391.1.331.1.281.1.191.1.101.1.11Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-1.2.1 | Hydra Booking <= 1.2.1 - Authenticated (Custom+) Insecure Direct Object Reference to Sensitive Information Exposure via 'booking_id' Parameter | July 8, 2026 | 1.2.2 | Medium |
*-1.1.44 | Hydra Booking — Appointment Scheduling & Booking Calendar <= 1.1.44 - Unauthenticated Stored Cross-Site Scripting | July 8, 2026 | 1.1.45 | High |
*-1.1.41 | Hydra Booking — Appointment Scheduling & Booking Calendar <= 1.1.41 - Missing Authorization | May 15, 2026 | 1.1.42 | Medium |
*-1.1.38 | Hydra Booking <= 1.1.38 - Authenticated (Hydra host+) Stored Cross-Site Scripting | February 15, 2026 | 1.1.39 | Medium |
*-1.1.32 | Hydra Booking <= 1.1.32 - Unauthenticated Privilege Escalation | January 21, 2026 | 1.1.33 | Critical |
*-1.1.32 | Hydra Booking <= 1.1.32 - Authenticated (Custom role+) SQL Injection | November 27, 2025 | 1.1.33 | Medium |
*-1.1.27 | Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment Bypass | November 10, 2025 | 1.1.28 | Medium |
*-1.1.27 | Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation | November 10, 2025 | 1.1.28 | Medium |
1.1.0-1.1.18 | Hydra Booking 1.1.0 - 1.1.18 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via tfhb_reset_password_callback Function | July 28, 2025 | 1.1.19 | High |
*-1.1.9 | Hydra Booking <= 1.1.9 - Missing Authorization | June 12, 2025 | 1.1.10 | Medium |
*-1.1.10 | Hydra Booking <= 1.1.10 - Authenticated (Subscriber+) SQL Injection | June 12, 2025 | 1.1.11 | Medium |
*-1.1.10 | Hydra Booking <= 1.1.10 - Authenticated (Contributor+) SQL Injection | June 5, 2025 | 1.1.11 | Medium |
Selected source records
Published: July 8, 2026
Published: July 8, 2026
Published: May 15, 2026
Published: February 15, 2026
Published: January 21, 2026
Published: November 27, 2025
Published: November 10, 2025
Published: November 10, 2025
Published: January 21, 2026
Published: July 28, 2025
Published: July 8, 2026
Published: November 27, 2025
Published: June 5, 2025
Published: June 12, 2025
Published: February 15, 2026
Published: November 10, 2025
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.