Vulnerabilities / Travelpayouts / WPSEC-2026-0672

Travelpayouts <= 1.2.3 - Missing Authorization to Authenticated (Subscriber+) Search Form Modification and Stored Cross-Site Scripting

Medium 6.4 CWE-862Fixed in 1.2.4
ID
WPSEC-2026-0672
Plugin
Travelpayouts (travelpayouts)
Affected
from 1.0.17 before 1.2.4
Remediation
Update to 1.2.4 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
Travelpayouts on WPSec AttackSurface
Fix released
Published

Description

The Travelpayouts plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.2.3 due to missing capability and nonce checks on the search form create, update and delete actions of the plugin's AJAX router. The widget code stored with a search form is output without escaping on every page that embeds the form. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create, change or delete the plugin's search forms and to inject arbitrary web scripts that execute whenever a user accesses a page that displays an affected search form.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0