Description
The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated users and gated only by a token the Tripzzy WordPress plugin before 1.5.1 issues to any anonymous visitor on request, allowing unauthenticated attackers to alter the contents, stored totals and notes of arbitrary bookings.
Published: 2026-09-20
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthenticated Booking Data Tampering
Action: Patch Immediately
AI Analysis

Impact

The Tripzzy WordPress plugin prior to version 1.5.1 fails to enforce any capability or ownership checks on its administrative booking‑management actions. The plugin issues a simple token to any anonymous visitor and relies on that token to gate administrative functions, allowing attackers with no credentials to modify booking contents, totals, and notes. This defect enables attackers to alter financial records and potentially manipulate customer data, leading to significant integrity and confidentiality breaches. The weakness stems from improper access control, allowing unauthorized data manipulation.

Affected Systems

WordPress sites that have the Tripzzy plugin installed and running a version earlier than 1.5.1 are affected. The vulnerability is specific to the plugin’s administrative booking‑management features and does not impact other components of the site directly. Site administrators should verify whether Tripzzy is present and determine the exact version deployed; if the version is older than 1.5.1, the site is vulnerable.

Risk and Exploitability

Because the vulnerability is exposed to unauthenticated users via a publicly accessible token endpoint, exploitation is straightforward for anyone who can reach the website. No CVSS or EPSS score is provided, but the potential for arbitrary data tampering suggests a high security impact. The flaw is not listed in the CISA KEV catalog, indicating that public exploitation may not be widespread yet, but the inherent lack of authentication control poses a serious risk. The attack surface is large, as the token and administrative actions are reachable by any visitor to the site’s front end.

Generated by OpenCVE AI on September 20, 2026 at 07:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Tripzzy plugin to version 1.5.1 or newer, which corrects the missing access controls.
  • If an update is not immediately possible, restrict access to the token issuance and booking‑management endpoints by applying web‑application firewall rules that allow only authenticated users or legitimate IP addresses.
  • Ensure the WordPress site requires user authentication before granting access to any administrative booking functions, and review all related hooks and shortcodes for additional access checks.

Generated by OpenCVE AI on September 20, 2026 at 07:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated users and gated only by a token the Tripzzy WordPress plugin before 1.5.1 issues to any anonymous visitor on request, allowing unauthenticated attackers to alter the contents, stored totals and notes of arbitrary bookings.
Title Tripzzy < 1.5.1 - Unauthenticated Booking Data Tampering
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-20T06:00:17.845Z

Reserved: 2026-09-09T11:22:38.094Z

Link: CVE-2026-87840

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-20T07:16:50.860

Modified: 2026-09-20T07:16:50.860

Link: CVE-2026-87840

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:00:08Z

Weaknesses