Impact
The vulnerability is a missing authorization flaw in Travon WP Flights & Hotels Booking WP Plugin that allows attackers to exploit incorrectly configured access control. This flaw can enable an attacker who has minimal access to directly manipulate booking functions or view sensitive data, effectively compromising the confidentiality and integrity of booking information and the overall plugin configuration.
Affected Systems
Travon WP Flights & Hotels Booking WP Plugin versions up to and including 3.1 are affected.
Risk and Exploitability
The CVSS score of 5.4 classifies the flaw as moderate severity, while the EPSS score of less than 1 % indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker can reach the plugin’s administrative interfaces, likely through authenticated user accounts or via the web interface; without a valid login or network access to those pages, the attack vector is limited.
OpenCVE Enrichment