VYPR

WpTravelly

by WordPress

CVEs (5)

  • CVE-2026-27089HigJun 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions.

  • CVE-2024-43212HigNov 1, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in MagePeople Team WpTravelly allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through 1.7.7.

  • CVE-2025-22737MedJan 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through <= 1.8.5.

  • CVE-2024-0434MedMay 29, 2024
    risk 0.34cvss 5.3epss 0.00

    The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ttbm_new_place_save' function in all versions up to, and including, 1.7.1. This makes it…

  • CVE-2024-32450MedApr 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team WpTravelly.This issue affects WpTravelly: from n/a through 1.6.0.