CVE-2026-27331
Description
Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WpTravelly: from n/a through 2.1.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in WpTravelly plugin versions up to 2.1.5 allows unauthenticated attackers to access higher-privileged functions.
Vulnerability
The WpTravelly plugin (tour-booking-manager) for WordPress contains a missing authorization vulnerability in versions from n/a through 2.1.5 [2]. This issue stems from incorrectly configured access control security levels, allowing functions that require higher privileges to be executed without proper capability or nonce checks [2].
Exploitation
An attacker needs no authentication or special network position, as the vulnerable endpoints are accessible to any visitor. The attacker can send crafted HTTP requests to the affected plugin's endpoints, triggering actions intended only for authenticated administrators without having valid credentials or nonce tokens [2].
Impact
Successful exploitation allows an unauthenticated attacker to execute higher-privileged actions within the plugin, such as modifying booking data, altering configuration, or accessing sensitive information. This leads to a compromise of the plugin's access control, potentially affecting availability and integrity of the travel booking system [2].
Mitigation
Fixed in version 2.1.6, released on 2026-05-22 according to the plugin repository [1]. Users are advised to update to version 2.1.6 or later immediately [2]. Patchstack users can enable auto-update for vulnerable plugins. No workarounds are provided; if unable to update immediately, disabling the plugin until the patch can be applied is recommended [2].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <= 2.1.5
- Range: <=2.1.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.