Travelpayouts [travelpayouts] <= 1.2.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in Travelpayouts Travelpayouts travelpayouts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travelpayouts: from n/a through <= 1.2.1.
- Affected:
- up to 1.2.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2026
CVE-2025-68042 on NVD →
Travelpayouts <= 1.2.3 - Missing Authorization
medium
The Travelpayouts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.2.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.2.3
- Fix:
- No patched version reported
- Disclosed:
- Jan 29, 2026
CVE-2025-68042 on NVD →
Travelpayouts [travelpayouts] < 1.1.17
unknown
[en] The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully tric...
- Affected:
- up to 1.1.17
- Fixed in:
- 1.1.17
- Disclosed:
- Mar 20, 2024
CVE-2024-0337 on NVD →
Travelpayouts: All Travel Brands in One Place <= 1.1.16 - Open Redirect
medium
The Travelpayouts: All Travel Brands in One Place plugin for WordPress is vulnerable to Open Redirect in versions 0.0.0.0 to 1.1.16. This is due to insufficient validation on the redirect url supplied via the travelpayouts_redirect parameter. This makes it possible for unauthenticated attackers to redirect users to pot...
- CVSS:
- 6.1
- Affected:
- up to 1.1.16
- Fixed in:
- 1.1.17
- Disclosed:
- Feb 28, 2024
CVE-2024-0337 on NVD →
Travelpayouts <= 1.1.12 - Cross-Site Request Forgery to Settings Import
medium
The Travelpayouts: All Travel Brands in One Place plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.12. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to import settings granted they can tr...
- CVSS:
- 4.3
- Affected:
- up to 1.1.12
- Fixed in:
- 1.1.13
- Disclosed:
- Jan 26, 2024
CVE-2023-5934 on NVD →
Travelpayouts <= 1.1.13 - Reflected Cross-Site Scripting
medium
The Travelpayouts: All Travel Brands in One Place plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.1.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- CVSS:
- 6.1
- Affected:
- up to 1.1.13
- Fixed in:
- 1.1.14
- Disclosed:
- Jan 23, 2024
CVE-2023-5932 on NVD →
Travelpayouts <= 1.0.16 - Cross-Site Request Forgery
high
The Travelpayouts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.16. This is due to missing or incorrect nonce validation in the outdated Redux Framework. This makes it possible for unauthenticated attackers to gain restricted access to administrative actions via...
- CVSS:
- 8.8
- Affected:
- up to 1.0.16
- Fixed in:
- 1.0.17
- Disclosed:
- Sep 13, 2021
Travelpayouts [travelpayouts] < 1.0.17
unknown
The Travelpayouts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.16. This is due to missing or incorrect nonce validation in the outdated Redux Framework. This makes it possible for unauthenticated attackers to gain restricted access to administrative actions via...
- Affected:
- up to 1.0.17
- Fixed in:
- 1.0.17
- Disclosed:
- Sep 13, 2021
Travelpayouts [travelpayouts] < 1.0.17
unknown
The plugin is using an outdated version of the Redux Framework (4.1.17), which is affected by CSRF bypass issues due to a logic flaw in the checks, allowing attacker to make logged in do unwanted actions
- Affected:
- up to 1.0.17
- Fixed in:
- 1.0.17
Travelpayouts [travelpayouts] < 1.1.14
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.1.14
- Fixed in:
- 1.1.14
CVE-2023-5932 on NVD →
Travelpayouts [travelpayouts] < 1.1.13
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.1.13
- Fixed in:
- 1.1.13
CVE-2023-5934 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database