plugin

Travelpayouts Vulnerabilities

11 known security issues reported for the Travelpayouts WordPress plugin. Most recent disclosed Feb 20, 2026.

1 high 4 medium

Running Travelpayouts on your site? Check whether your installed version is affected.

Scan your site free

Travelpayouts [travelpayouts] <= 1.2.1 (unfixed)

unknown

[en] Missing Authorization vulnerability in Travelpayouts Travelpayouts travelpayouts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travelpayouts: from n/a through <= 1.2.1.

Affected:
up to 1.2.1
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2025-68042 on NVD →

Travelpayouts <= 1.2.3 - Missing Authorization

medium

The Travelpayouts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.2.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.2.3
Fix:
No patched version reported
Disclosed:
Jan 29, 2026

CVE-2025-68042 on NVD →

Travelpayouts [travelpayouts] < 1.1.17

unknown

[en] The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully tric...

Affected:
up to 1.1.17
Fixed in:
1.1.17
Disclosed:
Mar 20, 2024

CVE-2024-0337 on NVD →

Travelpayouts: All Travel Brands in One Place <= 1.1.16 - Open Redirect

medium

The Travelpayouts: All Travel Brands in One Place plugin for WordPress is vulnerable to Open Redirect in versions 0.0.0.0 to 1.1.16. This is due to insufficient validation on the redirect url supplied via the travelpayouts_redirect parameter. This makes it possible for unauthenticated attackers to redirect users to pot...

CVSS:
6.1
Affected:
up to 1.1.16
Fixed in:
1.1.17
Disclosed:
Feb 28, 2024

CVE-2024-0337 on NVD →

Travelpayouts <= 1.1.12 - Cross-Site Request Forgery to Settings Import

medium

The Travelpayouts: All Travel Brands in One Place plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.12. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to import settings granted they can tr...

CVSS:
4.3
Affected:
up to 1.1.12
Fixed in:
1.1.13
Disclosed:
Jan 26, 2024

CVE-2023-5934 on NVD →

Travelpayouts <= 1.1.13 - Reflected Cross-Site Scripting

medium

The Travelpayouts: All Travel Brands in One Place plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.1.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

CVSS:
6.1
Affected:
up to 1.1.13
Fixed in:
1.1.14
Disclosed:
Jan 23, 2024

CVE-2023-5932 on NVD →

Travelpayouts <= 1.0.16 - Cross-Site Request Forgery

high

The Travelpayouts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.16. This is due to missing or incorrect nonce validation in the outdated Redux Framework. This makes it possible for unauthenticated attackers to gain restricted access to administrative actions via...

CVSS:
8.8
Affected:
up to 1.0.16
Fixed in:
1.0.17
Disclosed:
Sep 13, 2021

Travelpayouts [travelpayouts] < 1.0.17

unknown

The Travelpayouts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.16. This is due to missing or incorrect nonce validation in the outdated Redux Framework. This makes it possible for unauthenticated attackers to gain restricted access to administrative actions via...

Affected:
up to 1.0.17
Fixed in:
1.0.17
Disclosed:
Sep 13, 2021

Travelpayouts [travelpayouts] < 1.0.17

unknown

The plugin is using an outdated version of the Redux Framework (4.1.17), which is affected by CSRF bypass issues due to a logic flaw in the checks, allowing attacker to make logged in do unwanted actions

Affected:
up to 1.0.17
Fixed in:
1.0.17

Travelpayouts [travelpayouts] < 1.1.14

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.1.14
Fixed in:
1.1.14

CVE-2023-5932 on NVD →

Travelpayouts [travelpayouts] < 1.1.13

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.1.13
Fixed in:
1.1.13

CVE-2023-5934 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database