Impact
The vendor’s WpTravelly tour-booking-manager plugin contains a missing authorization check that allows a user to reach functions that should be restricted by access control lists. Because the access control is broken, an attacker could trigger administrative actions or read data that should be confined to privileged users. The weakness is catalogued as a broken access control (CWE-862).
Affected Systems
All WordPress installations that use the magepeopleteam WpTravelly plugin version 1.8.5 or earlier are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 marks this issue as moderate in severity. The EPSS score of less than 1% indicates a very low probability that exploitation will occur at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web interface or API endpoints of the plugin; the description does not specify authentication requirements, so it is inferred that an attacker may exploit the exposed endpoints without needing prior credentials if no checks are applied.
OpenCVE Enrichment
EUVD