Extension WordPress

Vulnérabilités Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Plugin

Cette page rassemble les failles publiées pour Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

9Vulnérabilités
0Critiques
9Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Plugin

9 fiches

CVE-2026-27089 Moyenne · 5,3
Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Plugin

Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution <= 2.1.7 – Missing Authorization

The Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to,…

Versions affectées

*-2.1.7

Correctif

2.1.8

Publication

01/06/2026

CVE-2026-27331 Moyenne · 4,3
Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Plugin

Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution <= 2.1.5 – Missing Authorization

The Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and…

Versions affectées

*-2.1.5

Correctif

2.1.6

Publication

26/05/2026

CVE-2026-39565 Moyenne · 4,3
Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Plugin

WpTravelly <= 2.1.7 – Missing Authorization

The WpTravelly plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above,…

Versions affectées

*-2.1.7

Correctif

2.1.8

Publication

21/03/2026

CVE-2025-30892 Élevée · 8,8
Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Plugin

WpTravelly <= 1.8.7 – Authenticated (Contributor+) PHP Object Injection

The WpTravelly plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.7 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a…

Versions affectées

*-1.8.7

Correctif

1.8.8

Publication

01/04/2025

CVE-2025-30891 Élevée · 8,8
Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Plugin

WpTravelly <= 1.8.7 – Authenticated (Contributor+) Local File Inclusion

The WpTravelly plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8.7. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…

Versions affectées

*-1.8.7

Correctif

1.8.8

Publication

27/03/2025

CVE-2025-22737 Moyenne · 5,3
Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Plugin

WpTravelly <= 1.8.5 – Missing Authorization

The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in all versions up to, and including, 1.8.5. This makes…

Versions affectées

*-1.8.5

Correctif

1.8.6

Publication

14/01/2025

CVE-2024-43212 Moyenne · 5,3
Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Plugin

WpTravelly <= 1.7.7 – Missing Authorization

The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ttbm_trash_post() function in all versions up to, and including, 1.7.7. This…

Versions affectées

*-1.7.7

Correctif

1.7.8

Publication

09/08/2024

CVE-2024-0434 Moyenne · 5,3
Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Plugin

WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly <= 1.7.1 – Missing Authorization via ttbm_new_place_save

The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ttbm_new_place_save' function in all versions up to, and including,…

Versions affectées

*-1.7.1

Correctif

1.7.2

Publication

28/05/2024

CVE-2024-32450 Moyenne · 4,3
Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Plugin

WpTravelly <= 1.6.0 – Cross-Site Request Forgery

The WpTravelly plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.0. This is due to missing or incorrect nonce validation on the quick_setup() function. This makes it possible for unauthenticated attackers…

Versions affectées

*-1.6.0

Correctif

1.6.1

Publication

12/04/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités