Impact
The vulnerability permits unauthenticated users to bypass authentication checks in WordPress WpTravelly plugin versions 2.1.7 and earlier. Based on the description, it is inferred that the attack vector involves accessing the plugin's web interface. By exploiting flaw(s) in the plugin's authorization logic, an attacker can cause the system to treat requests as if they originated from an authenticated administrator, allowing execution of privileged functions. This is identified as CWE‑290, an authorization bypass through user‑controlled input or state.
Affected Systems
The affected product is the WordPress WpTravelly plugin supplied by Magepeople Inc. Versions up to and including 2.1.7 contain the flaw. Any WordPress installation that has this plugin installed and is running a vulnerable version is at risk. The vulnerability is limited to the WpTravelly plugin itself and does not affect the core WordPress software or other plugins.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the flaw is exploitable remotely via a web interface and does not require authentication or auxiliary credentials, enabling an attacker to reach it from anywhere on the public internet. The key prerequisites are simply a WordPress site with the vulnerable WpTravelly plugin installed.
OpenCVE Enrichment