Impact
The vulnerability is a missing authorization flaw that allows attackers to exploit incorrectly configured access control security levels within the WordPress WpTravelly plugin. This flaw can let attackers interact with the plugin’s internal functions without proper authentication, potentially allowing unauthorized creation, modification, or deletion of tour bookings and exposure of sensitive booking data. The weakness falls under CWE‑862, which means the application fails to enforce required permissions on protected resources.
Affected Systems
Magepeople inc. releases the WpTravelly tour‑booking‑manager plugin for WordPress. Versions from the earliest available through 2.3.1 are vulnerable. The plugin is commonly deployed on WordPress sites that manage tour and travel bookings.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. No EPSS data is available and the issue is not listed in the CISA KEV catalog, but the absence of access controls implies a realistic attack vector through the web interface. An attacker could dispatch crafted HTTP requests to the plugin’s endpoints that bypass the normal permission checks, potentially gaining full control of booking data or administrative functions. The exploit requires only that the target site hosts a vulnerable version of the plugin, and it does not require user interaction.
OpenCVE Enrichment