VYPR

Wp Travel

by WordPress

Source repositories

CVEs (16)

  • CVE-2026-4290CriMay 29, 2026
    risk 0.59cvss 9.1epss 0.00

    The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and…

  • CVE-2026-45218HigMay 12, 2026
    risk 0.50cvss 7.7epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows Blind SQL Injection.This issue affects WP Travel: from n/a through <= 11.4.0.

  • CVE-2025-22691HigFeb 3, 2025
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows SQL Injection.This issue affects WP Travel: from n/a through <= 10.1.3.

  • CVE-2023-47224HigJan 2, 2025
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through <= 7.8.0.

  • CVE-2026-81796HigSep 10, 2026
    risk 0.47cvss 7.3epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in WEN Solutions WP Travel wp-travel allows Password Recovery Exploitation.This issue affects WP Travel: from n/a through 12.0.3.

  • CVE-2024-53813MedDec 6, 2024
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through <= 9.6.0.

  • CVE-2024-44039MedOct 6, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel WP Travel wp-travel allows Stored XSS.This issue affects WP Travel: from n/a through <= 9.3.1.

  • CVE-2024-12067MedJan 9, 2025
    risk 0.35cvss 6.5epss 0.00

    The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injection via the 'booking_itinerary' parameter of the 'wptravel_get_booking_data' function in all versions up to, and including, 10.0.0 due to insufficient…

  • CVE-2026-18042MedSep 9, 2026
    risk 0.34cvss 5.3epss 0.00

    The WP Travel WordPress plugin before 12.0.2 does not verify that the requester is authorized to act on the booking targeted by one of its front-end payment-message handlers, allowing unauthenticated attackers to cancel the payment on any customer's booking.

  • CVE-2026-24568MedJan 23, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through <= 11.1.0.

  • CVE-2026-13146LowSep 9, 2026
    risk 0.24cvss 3.7epss 0.00

    The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address to change that customer's booking payment…

  • CVE-2026-13144LowSep 9, 2026
    risk 0.24cvss 3.7epss 0.00

    The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the targeted booking on one branch of its bank-deposit handler, allowing an unauthenticated attacker who knows the target customer's email address to reset that…

  • CVE-2021-4389MedJul 1, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Travel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.6. This is due to missing or incorrect nonce validation on the save_meta_data() function. This makes it possible for unauthenticated attackers to save metadata…

  • CVE-2026-13145MedJul 30, 2026
    risk 0.00cvss 4.3epss 0.00

    The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an…

  • CVE-2026-13143MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid…

  • CVE-2026-11868MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.