What is CVE-2026-15948?
CVE-2026-15948 is a Stored Cross-Site Scripting (XSS) vulnerability in the Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress via the 'first_name' parameter. Affecting versions up to 1.2.2 due to insufficient input sanitization and output escaping, this allows authenticated users to inject malicious scripts. Users should update to the latest patched version immediately.
Azərbaycanca: CVE-2026-15948, Hydra Booking - WordPress üçün Appointment Scheduling & Booking Calendar plaginində aşkar edilmiş Stored Cross-Site Scripting (XSS) zəifliyidir. Bu boşluq 'first_name' parametrinin düzgün təmizlənməməsi səbəbindən 1.2.2 və aşağı versiyalara təsir edir. İstifadəçilər plagini ən son təhlükəsiz versiyaya yeniləməli və giriş yoxlamalarını gücləndirməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which parameter is exploited in the CVE-2026-15948 vulnerability for the Hydra Booking plugin?
The CVE-2026-15948 vulnerability is exploited via the 'first_name' parameter due to insufficient sanitization, allowing Stored XSS attacks.
Which versions of the Hydra Booking plugin are affected by CVE-2026-15948?
This vulnerability affects Hydra Booking plugin versions up to and including 1.2.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.