CVE-2026-15948 | themefic Hydra Booking Plugin up to 1.2.2 on WordPress Signup Shortcode first_name cross site scripting

SecurityVulns

A vulnerability was found in themefic Hydra Booking Plugin up to 1.2.2 on WordPress and classified as problematic. This affects an unknown function of the component Signup Shortcode. The manipulation of the argument first_name results in cross site scripting.

This vulnerability is identified as CVE-2026-15948. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More