PT-2026-49359 · Magepeople+1 · Wptravelly+1

CVE-2026-27089

·

Published

2026-06-01

·

Updated

2026-06-15

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions WpTravelly versions prior to 2.1.8
Description The Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution plugin for WordPress allows unauthorized access because it lacks a capability check in a specific function. This flaw enables unauthenticated attackers to perform unauthorized actions.
Recommendations Update WpTravelly to version 2.1.8 or later.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27089

Affected Products

Wptravelly
Tour-Booking-Manager