Description
Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects WpTravelly: from n/a through 2.1.5.
Published: 2026-05-26
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows an attacker to gain unauthorized access to protected parts of the WpTravelly plugin. The defect permits abuse of incorrectly configured access control levels, which could give attackers visibility or modification rights that should be protected. Because the weakness is a classic broken access control (CWE‑862), the attacker may exploit it to read sensitive booking data, change settings, or otherwise alter the application’s state, potentially impacting data confidentiality and integrity. No direct denial of service or remote code execution is described, but the compromise of the plugin’s data could have business impact.

Affected Systems

This flaw affects the Magepeople inc. WpTravelly WordPress plugin for all versions from the initial release up to and including 2.1.5. It does not apply to 2.1.6 or newer releases that include the fix.

Risk and Exploitability

The CVSS score of 6.3 indicates a medium severity vulnerability. The EPSS score is not available, so the current exploitation probability is unknown. Because the flaw is not listed in CISA KEV, no known public exploits have been reported. The likely attack vector is a web-based request from an authenticated or unauthenticated attacker who can interact with the plugin’s pages. Exploitation would require the attacker to discover that the plugin allows access to restricted resources and then submit the appropriate request. As the issue is a broken access control, the potential incident could lead to unauthorized data exposure and data tampering. The overall risk therefore hinges on the attacker’s ability to interact with the affected site and the sensitivity of the data stored by the plugin.

Generated by OpenCVE AI on May 26, 2026 at 20:22 UTC.

Remediation

Vendor Solution

Update the WordPress WpTravelly Plugin to the latest available version (at least 2.1.6).


OpenCVE Recommended Actions

  • Update WpTravelly to version 2.1.6 or later to remove the broken access control flaw.
  • If an update is not immediately possible, disable the plugin’s restricted features or restrict access through a web application firewall or role‑based access controls.
  • Audit the site’s user permissions and ensure only authorized accounts can access booking-related functions; remove any unnecessary administrative or editor roles that might exploit this flaw.

Generated by OpenCVE AI on May 26, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Magepeople
Magepeople wptravelly
Wordpress
Wordpress wordpress
Vendors & Products Magepeople
Magepeople wptravelly
Wordpress
Wordpress wordpress

Tue, 26 May 2026 19:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpTravelly: from n/a through 2.1.5.
Title WordPress WpTravelly plugin <= 2.1.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Magepeople Wptravelly
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-26T19:29:09.970Z

Reserved: 2026-02-19T09:51:27.898Z

Link: CVE-2026-27331

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-05-26T20:16:17.073

Modified: 2026-05-26T20:19:21.240

Link: CVE-2026-27331

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T20:30:15Z

Weaknesses