VYPR

Wp Travel

by WordPress

Source repositories

CVEs (12)

  • CVE-2026-4290CriMay 29, 2026
    risk 0.59cvss 9.1epss 0.00

    The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and…

  • CVE-2026-45218HigMay 12, 2026
    risk 0.50cvss 7.7epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows Blind SQL Injection.This issue affects WP Travel: from n/a through <= 11.4.0.

  • CVE-2025-22691HigFeb 3, 2025
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows SQL Injection.This issue affects WP Travel: from n/a through <= 10.1.3.

  • CVE-2023-47224HigJan 2, 2025
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through <= 7.8.0.

  • CVE-2024-53813MedDec 6, 2024
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through <= 9.6.0.

  • CVE-2024-44039MedOct 6, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel WP Travel wp-travel allows Stored XSS.This issue affects WP Travel: from n/a through <= 9.3.1.

  • CVE-2024-12067MedJan 9, 2025
    risk 0.35cvss 6.5epss 0.00

    The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injection via the 'booking_itinerary' parameter of the 'wptravel_get_booking_data' function in all versions up to, and including, 10.0.0 due to insufficient…

  • CVE-2026-24568MedJan 23, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through <= 11.1.0.

  • CVE-2021-4389MedJul 1, 2023
    risk 0.21cvss 4.3epss 0.00

    The WP Travel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.6. This is due to missing or incorrect nonce validation on the save_meta_data() function. This makes it possible for unauthenticated attackers to save metadata…

  • CVE-2026-13145MedJul 30, 2026
    risk 0.00cvss 4.3epss 0.00

    The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an…

  • CVE-2026-13143MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid…

  • CVE-2026-11868MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.