{"id":"CVE-2026-92421","published":"2026-09-19T07:16:34.000","lastModified":"2026-09-21T13:34:57.127","description":"The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3-assigned host role to modify other hosts' profile data and reassign ownership of another host's record to themselves.","cvssScore":4.7,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","cwes":["CWE-639"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/3ba305b9-5f3b-47eb-a5d7-ddbeeeefd0a4/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}