medium · CVSS v3 5.3 · EPSS 0.00136
CVE-2026-87840
The Tripzzy WordPress plugin before version 1.5.1 fails to enforce capability checks on booking‑management actions, exposing them to unauthe
Overview
The Tripzzy WordPress plugin before version 1.5.1 fails to enforce capability checks on booking‑management actions, exposing them to unauthenticated users via a token that any visitor can obtain. This flaw allows attackers to modify booking contents, totals, and notes without authorization. The vulnerability can lead to unauthorized data manipulation on affected WordPress sites.
Description
The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated users and gated only by a token the Tripzzy WordPress plugin before 1.5.1 issues to any anonymous visitor on request, allowing unauthenticated attackers to alter the contents, stored totals and notes of arbitrary bookings.
Impact
Integrity of booking data is compromised, enabling attackers to alter reservations, totals, and notes. Confidentiality may be affected if sensitive booking details are exposed. Availability can be impacted if manipulated data disrupts booking workflows. WordPress site administrators, booking managers, and customers are directly impacted.
Remediation
Update the Tripzzy plugin to version 1.5.1 or later, which implements proper capability checks. If an update is not immediately possible, disable or restrict the booking‑management endpoints to authenticated users only, block the token issuance endpoint, and enforce role‑based access controls. Monitor booking logs for unauthorized changes and apply any vendor‑issued patches promptly.
Risk context
The vulnerability has a medium severity score (CVSS v3 5.3) and a very low EPSS of 0.00136, indicating a low likelihood of exploitation but still requiring timely remediation to prevent data integrity issues.
Affected products
- Tripzzy WordPress plugin 1.5.0 and earlier
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- 0.00136