{"id":"CVE-2026-92420","published":"2026-09-19T07:16:33.893","lastModified":"2026-09-21T13:34:57.127","description":"The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on the same site.","cvssScore":3.8,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","cwes":["CWE-639"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/3685e160-f3a4-4772-b2e3-f6155894ab4c/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}