Access Control Vulnerability in WpTravelly Tour Booking Manager by Magepeople Inc.
CVE-2026-62063

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 October 2026

What is CVE-2026-62063?

A missing authorization vulnerability was identified in the WpTravelly tour booking manager plugin developed by Magepeople Inc. This flaw arises from incorrectly configured access control security levels, allowing potential attackers to exploit system weaknesses. Users running affected versions may find their tour booking management processes compromised, as unauthorized access could lead to sensitive data exposure or inappropriate actions within the application. It is crucial for users to promptly assess their installations and apply necessary updates to mitigate these risks.

Affected Version(s)

WpTravelly 0 <= 2.3.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ori Ashkenazi (tarzeh) | Patchstack Bug Bounty Program
.