
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68027 is an Incorrect Privilege Assignment vulnerability in the Themefic Hydra Booking WordPress plugin that allows unauthenticated attackers to perform privilege escalation. It affects all versions of the Hydra Booking plugin up to and including version 1.1.32. The vulnerability was published on January 22, 2026, and was reported by Patchstack. It carries a CVSS v3.1 base score of 7.3 (High), assigned by CISA-ADP (Patchstack).
The vulnerability is classified under CWE-266 (Incorrect Privilege Assignment), meaning the plugin incorrectly assigns or fails to properly restrict privilege levels during certain operations, enabling unauthorized privilege escalation. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by remote unauthenticated attackers. The precise code-level mechanism (e.g., a specific REST API endpoint or registration hook that assigns elevated roles) has not been publicly detailed beyond the Patchstack advisory (Patchstack).
Successful exploitation allows an unauthenticated remote attacker to escalate their privileges on the affected WordPress site, potentially gaining administrative or elevated user roles. This could result in unauthorized access to sensitive site data (confidentiality impact: low), modification of site content or settings (integrity impact: low), and potential disruption of site availability (availability impact: low). In a worst-case scenario, privilege escalation to an administrator role could lead to full site compromise, installation of backdoors, or further lateral movement within a shared hosting environment (Patchstack).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-68027 as of the available data. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been identified (Patchstack).
Users should update the Hydra Booking WordPress plugin to a version beyond 1.1.32 that addresses this vulnerability. Site administrators should audit user accounts for any unexpected role assignments or newly created privileged accounts. If an updated version is not yet available, consider temporarily deactivating the plugin until a patch is released. Monitor the WordPress plugin repository and Themefic's official channels for patch announcements (Patchstack).
The vulnerability was noted in Wordfence's weekly WordPress vulnerability report for the week of January 19–25, 2026, indicating routine coverage within the WordPress security community (Wordfence Blog). No significant vendor statements, notable researcher commentary, or broader media coverage beyond standard vulnerability tracking has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."