Impact
The Tripzzy WordPress plugin prior to version 1.5.1 fails to enforce any capability or ownership checks on its administrative booking‑management actions. The plugin issues a simple token to any anonymous visitor and relies on that token to gate administrative functions, allowing attackers with no credentials to modify booking contents, totals, and notes. This defect enables attackers to alter financial records and potentially manipulate customer data, leading to significant integrity and confidentiality breaches. The weakness stems from improper access control, allowing unauthorized data manipulation.
Affected Systems
WordPress sites that have the Tripzzy plugin installed and running a version earlier than 1.5.1 are affected. The vulnerability is specific to the plugin’s administrative booking‑management features and does not impact other components of the site directly. Site administrators should verify whether Tripzzy is present and determine the exact version deployed; if the version is older than 1.5.1, the site is vulnerable.
Risk and Exploitability
Because the vulnerability is exposed to unauthenticated users via a publicly accessible token endpoint, exploitation is straightforward for anyone who can reach the website. No CVSS or EPSS score is provided, but the potential for arbitrary data tampering suggests a high security impact. The flaw is not listed in the CISA KEV catalog, indicating that public exploitation may not be widespread yet, but the inherent lack of authentication control poses a serious risk. The attack surface is large, as the token and administrative actions are reachable by any visitor to the site’s front end.
OpenCVE Enrichment