CVE-2023-47224

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 2, 2025
CWE ID 862

Summary

CVE-2023-47224 is a critical vulnerability affecting WP Travel, a popular travel booking plugin for WordPress. The issue stems from missing authorization checks, which allows unauthorized users to access restricted functionality. Specifically, WP Travel fails to enforce proper access control security levels, potentially enabling attackers to exploit this weakness. This vulnerability affects WP Travel versions from n/a through 7.8.0, putting a significant number of websites using this plugin at risk. It is crucial for WP Travel users to update their plugins to the latest patched version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share