Junglewise Threat Intelligence

CVE-2026-87840: Tripzzy WordPress plugin unauthenticated booking data tampering

CVE-2026-87840 · Severity: medium · CVSS 5.3 · Published 2026-09-20

Executive brief

The Tripzzy WordPress plugin issues a security token to any anonymous visitor and does not validate permissions on booking management actions, allowing unauthenticated attackers to modify booking details. An attacker can alter booking contents, totals, and notes for any booking in the system without logging in, compromising the integrity of reservation and transaction records.

Technical details

The plugin exposes administrative booking-management actions to unauthenticated users, gated only by a token issued to any anonymous visitor on request, with no capability or ownership checks performed. An unauthenticated attacker can obtain this token and use it to invoke administrative actions to alter arbitrary bookings, including their contents, stored totals, and notes. The vulnerability stems from broken access control (CWE-284) where CSRF/token-based protection is insufficient without proper permission validation.

Affected products

  • Tripzzy Tripzzy WordPress plugin before 1.5.1

Timeline

  • 2026-09-18: disclosed
  • 2026-09-20: patched: Fixed in version 1.5.1

References