CVE-2026-28186: WordPress Travelfic Toolkit plugin <= 1.5.1 - Broken Access Control vulnerability
Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Travelfic Toolkit pluginto a version that resolves this vulnerability.Fixed in 1.5.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28186?
The severity of CVE-2026-28186 is rated as high, with a CVSS score of 8.1.
What type of vulnerability is CVE-2026-28186?
CVE-2026-28186 is a Broken Access Control vulnerability in the Travelfic Toolkit plugin.
How can I fix CVE-2026-28186?
To fix CVE-2026-28186, update the Travelfic Toolkit plugin to version 1.5.2 or later.
Who is affected by CVE-2026-28186?
Users with the Travelfic Toolkit plugin version 1.5.1 or earlier installed on their WordPress sites are affected by CVE-2026-28186.
What do the access vector and access complexity ratings mean for CVE-2026-28186?
CVE-2026-28186 has an attack vector of network, low access complexity, and requires a user to authenticate, indicating that it can be exploited remotely by a legitimate user.