Description
The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking cancellation in all versions up to, and including, 1.1.27. This is due to the plugin's "tfhb_meeting_form_submit_callback" function using insufficiently random values to generate booking cancellation tokens, combined with a globally shared nonce. This makes it possible for unauthenticated attackers to cancel arbitrary bookings via brute force attacks against the tfhb_meeting_form_cencel AJAX endpoint.
INFO
Published Date :
2025-11-11T11:03:45.316Z
Last Modified :
2026-04-08T16:50:23.131Z
Source :
Wordfence
AFFECTED PRODUCTS
The following products are affected by CVE-2025-12787 vulnerability.
| Vendors | Products |
|---|---|
| Themefic |
|
| Wordpress |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-12787.