# Travelpayouts <= 1.2.3 - Missing Authorization to Authenticated (Subscriber+) Search Form Modification and Stored Cross-Site Scripting

- **ID:** WPSEC-2026-0672
- **Plugin:** Travelpayouts (`travelpayouts`), https://wordpress.org/plugins/travelpayouts/
- **Affected versions:** from 1.0.17 before 1.2.4
- **Fixed in:** 1.2.4 (Update to 1.2.4 or later.)
- **Severity:** Medium 6.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/travelpayouts
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0672/

## Description

The Travelpayouts plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.2.3 due to missing capability and nonce checks on the search form create, update and delete actions of the plugin's AJAX router. The widget code stored with a search form is output without escaping on every page that embeds the form. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create, change or delete the plugin's search forms and to inject arbitrary web scripts that execute whenever a user accesses a page that displays an affected search form.

## References

- https://wpsec.com/vuln/WPSEC-2026-0672/
- https://plugins.svn.wordpress.org/travelpayouts/tags/1.2.4/
- https://wordpress.org/plugins/travelpayouts/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0672/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
