Executive brief
WpTravelly is a WordPress plugin used for managing tour bookings and travel services. A security flaw in the plugin's access control settings allows logged-in users with low-level permissions, such as subscribers, to perform actions they should not be authorized to do. This could lead to unauthorized changes to booking data or plugin configurations, potentially disrupting business operations.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the magepeopleteam WpTravelly (tour-booking-manager) plugin for WordPress. The flaw is rooted in incorrectly configured access control security levels within the plugin's functional components. An attacker with a low-privileged account (Subscriber level) can exploit this to execute actions or access data that should be restricted to higher-privileged users. The vulnerability is reachable over the network without user interaction, provided the attacker is authenticated. The issue is addressed in version 2.1.8.
Affected products
- magepeopleteam WpTravelly (tour-booking-manager) <= 2.1.7
Timeline
- 2026-02-19: other: Vulnerability reported by researcher
- 2026-03-21: advisory: Patchstack advisory published
- 2026-04-08: disclosed: CVE published
- 2026-02-19: patched: Fixed in version 2.1.8