First published: Wed Jan 15 2025(Updated: )
Missing Authorization vulnerability in MagePeople Team WpTravelly allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through 1.8.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress WpTravelly Plugin | <=1.8.5 | |
MagePeople WpTravelly | <=1.8.5 |
Update the WordPress WpTravelly wordpress plugin to the latest available version (at least 1.8.6).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22737 has a high severity due to the missing authorization flaw that allows unauthorized access to restricted functionalities.
To fix CVE-2025-22737, update the WpTravelly plugin to the latest version beyond 1.8.5 to address the broken access control vulnerability.
CVE-2025-22737 affects the WpTravelly plugin versions up to and including 1.8.5.
Yes, CVE-2025-22737 can potentially lead to unauthorized access to sensitive functionalities and data.
CVE-2025-22737 is a specific vulnerability related to the WpTravelly plugin and may not be as common as other vulnerabilities but poses significant risks to affected systems.