Executive brief
WpTravelly is a WordPress plugin used for managing tour bookings and travel reservations. A security flaw in versions 2.1.7 and earlier allows unauthorized individuals to bypass security restrictions, potentially allowing them to modify data or perform actions without proper authentication. This could lead to unauthorized changes in booking information or system settings.
Technical details
The WpTravelly plugin for WordPress (also known as Tour Booking Manager) is vulnerable to an authentication bypass by spoofing (CWE-290) in versions up to 2.1.7. The vulnerability allows a remote, unauthenticated attacker to bypass security restrictions and perform unauthorized actions that typically require higher privileges. Based on the CVSS vector, the impact is primarily on integrity (High), while confidentiality and availability are not directly affected. The issue was addressed in version 2.1.8.
Affected products
- Magepeople inc. WpTravelly (Tour Booking Manager) <= 2.1.7
Timeline
- 2025-12-09: other: Reported by researcher benzdeus
- 2026-06-01: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date
- 2026-06-01: patched: Version 2.1.8 released