Impact
Travelpayouts WordPress plugin contains a missing authorization flaw, allowing users to bypass intended access controls and interact with restricted plugin functions. The weakness is identified as CWE-862 (Missing Authorization). Depending on the plugin’s configuration, an attacker could potentially read, modify, or delete data exposed by the plugin, thereby compromising the confidentiality and integrity of site content and potentially escalating privileges to higher levels within the WordPress environment.
Affected Systems
The affected product is the Travelpayouts plugin for WordPress. All installations running version 1.2.2 or earlier are vulnerable, including any unreleased or unspecified builds that fall within the range n/a through <=1.2.2.
Risk and Exploitability
The CVSS score of 6.5 classifies this issue as a medium severity vulnerability. The EPSS score of less than 1% indicates a low probability of exploitation at present, and the vulnerability has not been catalogued in CISA’s KEV database. The attack vector is most likely via the web interface of the plugin, where user input is not properly verified against the user’s role, enabling an unauthorized user to exploit administrative or management endpoints.
OpenCVE Enrichment