CVE-2026-27331: WordPress WpTravelly plugin <= 2.1.5 - Broken Access Control vulnerability
Published May 26, 2026
·Updated
Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WpTravelly: from n/a through 2.1.5.
Affected Software
1 affected component
MagePeople WpTravelly<=2.1.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WpTravelly pluginto a version that resolves this vulnerability.Fixed in 2.1.6
Event History
May 26, 2026
CVE Published
via MITRE·07:29 PM
Data Sourced
via MITRE·07:29 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27331?
The severity of CVE-2026-27331 is rated medium with a score of 6.3.
2
How do I fix CVE-2026-27331?
To fix CVE-2026-27331, update the WordPress WpTravelly Plugin to the latest available version, at least 2.1.6.
3
What type of vulnerability is CVE-2026-27331?
CVE-2026-27331 is identified as a Broken Access Control vulnerability.
4
Which versions of WpTravelly are affected by CVE-2026-27331?
CVE-2026-27331 affects all versions of WpTravelly from n/a through 2.1.5.
5
Who is the vendor for the CVE-2026-27331 vulnerability?
The vendor for CVE-2026-27331 is MagePeople.