Unauthenticated Booking Management Vulnerability in Tripzzy WordPress Plugin
CVE-2026-87840
Currently unrated
Key Information:
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2026-87840?
The Tripzzy WordPress plugin prior to version 1.5.1 lacks essential capability and ownership checks for its booking management functionalities. As a result, these actions are mistakenly accessible to unauthenticated users. The plugin generates a token for any visitor, which can potentially be exploited by attackers to manipulate booking data, including changing stored totals and notes. This vulnerability poses a significant risk, enabling unauthorized users to compromise the integrity of booking information.
Affected Version(s)
Tripzzy 1.3.4 < 1.5.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.