{
 "id": "WPSEC-2026-0672",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0672/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0672/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0672/index.md",
 "title": "Travelpayouts <= 1.2.3 - Missing Authorization to Authenticated (Subscriber+) Search Form Modification and Stored Cross-Site Scripting",
 "description": "The Travelpayouts plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.2.3 due to missing capability and nonce checks on the search form create, update and delete actions of the plugin's AJAX router. The widget code stored with a search form is output without escaping on every page that embeds the form. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create, change or delete the plugin's search forms and to inject arbitrary web scripts that execute whenever a user accesses a page that displays an affected search form.",
 "plugin": {
  "slug": "travelpayouts",
  "name": "Travelpayouts",
  "full_name": "Travelpayouts",
  "wordpress_org": "https://wordpress.org/plugins/travelpayouts/",
  "advisories_url": "https://wpsec.com/vuln/plugin/travelpayouts/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/travelpayouts"
 },
 "type": "XSS",
 "cwe": [
  "CWE-862"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.4,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.0.17",
    "from_inclusive": true,
    "to": "1.2.4",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.0.17 before 1.2.4"
  ]
 },
 "introduced_in": "1.0.17",
 "fixed_in": "1.2.4",
 "remediation": "Update to 1.2.4 or later.",
 "fix_released": "2026-10-07T18:23:33+00:00",
 "published": "2026-10-08T18:42:43+00:00",
 "updated": "2026-10-08T07:40:44.139425+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0672/",
  "https://plugins.svn.wordpress.org/travelpayouts/tags/1.2.4/",
  "https://wordpress.org/plugins/travelpayouts/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/travelpayouts",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}