Travelpayouts <= 1.2.3 - Missing Authorization to Authenticated (Subscriber+) Search Form Modification and Stored Cross-Site Scripting
- ID
- WPSEC-2026-0672
- Plugin
- Travelpayouts (travelpayouts)
- Affected
- from 1.0.17 before 1.2.4
- Remediation
- Update to 1.2.4 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- Travelpayouts on WPSec AttackSurface
- Fix released
- Published
Description
The Travelpayouts plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.2.3 due to missing capability and nonce checks on the search form create, update and delete actions of the plugin's AJAX router. The widget code stored with a search form is output without escaping on every page that embeds the form. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create, change or delete the plugin's search forms and to inject arbitrary web scripts that execute whenever a user accesses a page that displays an affected search form.
References
- https://wpsec.com/vuln/WPSEC-2026-0672/
- https://plugins.svn.wordpress.org/travelpayouts/tags/1.2.4/
- https://wordpress.org/plugins/travelpayouts/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS