Impact
The vulnerability is an authentication bypass that allows attackers to trigger password‑recovery mechanisms and log in without valid credentials. This flaw permits unauthenticated access to the WordPress site, exposing all actions the authenticated role can perform. It is classified as an authentication weakness (CWE‑288) and can be exploited to create or modify content, adjust plugin settings, or manage users.
Affected Systems
The vulnerability affects the WEN Solutions WP Travel plugin, versions 12.0.3 and earlier. Any WordPress site that has these plugin versions installed is potentially exposed. Updated or higher versions are not affected.
Risk and Exploitability
The CVSS score of 7.3 indicates a high likelihood of serious impact. EPSS score is <1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA KEV, suggesting no confirmed widespread exploitation. Based on the description, it is inferred that attackers can exploit the flaw by sending crafted requests to the plugin’s authentication endpoints exposed over the public web interface. Based on the description, it is inferred that no privilege escalation beyond what the authenticated user would normally possess is required, so the risk is highest for sites with weak or default account protections.
OpenCVE Enrichment