CVE-2026-62063: WordPress WpTravelly plugin <= 2.3.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Magepeople inc. WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through 2.3.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WpTravelly pluginto a version that resolves this vulnerability.Fixed in 2.3.2
Event History
Frequently Asked Questions
Who can exploit this issue?
The published severity vector indicates that an attacker needs low-level privileges (PR:L). The attack can be performed over the network, requires no user interaction, and has low attack complexity.
What is the potential impact?
Successful exploitation can affect integrity and availability at a low level. No confidentiality impact is identified in the supplied severity vector.
Which WpTravelly versions are affected?
WpTravelly versions through 2.3.1 are affected. The available data does not identify a fixed version.