The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking cancellation in all versions up to, and including, 1.1.27. This is due to the plugin's "tfhb_meeting_form_submit_callback" function using insufficiently random values to generate booking cancellation tokens, combined with a globally shared nonce. This makes it possible for unauthenticated attackers to cancel arbitrary bookings via brute force attacks against the tfhb_meeting_form_cencel AJAX endpoint.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themefic
Themefic hydra Booking Wordpress Wordpress wordpress |
|
| Vendors & Products |
Themefic
Themefic hydra Booking Wordpress Wordpress wordpress |
Tue, 11 Nov 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking cancellation in all versions up to, and including, 1.1.27. This is due to the plugin's "tfhb_meeting_form_submit_callback" function using insufficiently random values to generate booking cancellation tokens, combined with a globally shared nonce. This makes it possible for unauthenticated attackers to cancel arbitrary bookings via brute force attacks against the tfhb_meeting_form_cencel AJAX endpoint. | |
| Title | Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation | |
| Weaknesses | CWE-330 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-11-14T15:29:36.323Z
Reserved: 2025-11-05T23:23:11.777Z
Link: CVE-2025-12787
Updated: 2025-11-14T15:24:04.618Z
Status : Awaiting Analysis
Published: 2025-11-11T11:15:34.673
Modified: 2025-11-12T16:19:34.210
Link: CVE-2025-12787
No data.