Executive brief
WpTravelly is a WordPress plugin used for managing tour bookings and travel services. A security flaw in the plugin allows users with low-level accounts to bypass access controls and perform actions they should not be authorized to do. This could lead to unauthorized changes to booking data or access to restricted administrative functions, potentially disrupting business operations.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Magepeople inc. WpTravelly plugin for WordPress through version 2.1.5. The flaw stems from insufficient access control checks on certain functions, allowing an authenticated attacker with 'Contributor' level privileges to execute actions intended for higher-privileged users. The attack can be carried out over the network without user interaction. Successful exploitation could allow an attacker to modify settings or data within the plugin's scope. The issue is resolved in version 2.1.6.
Affected products
- Magepeople inc. WpTravelly (Tour Booking Manager) n/a through 2.1.5
Timeline
- 2025-12-04: other: Vulnerability reported by researcher johska
- 2026-05-26: advisory: Advisory published by Patchstack and NVD
- 2026-05-26: patched: Patch released in version 2.1.6