CVE-2026-87840
Received Received - Intake

Unauthenticated Booking Modification in Tripzzy WordPress Plugin

Vulnerability report for CVE-2026-87840, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-20

Last updated on: 2026-09-20

Assigner: WPScan

Description

The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated users and gated only by a token the Tripzzy WordPress plugin before 1.5.1 issues to any anonymous visitor on request, allowing unauthenticated attackers to alter the contents, stored totals and notes of arbitrary bookings.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-20
Last Modified
2026-09-20
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tripzzy wordpress_plugin to 1.5.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Tripzzy WordPress plugin before version 1.5.1 has a vulnerability where administrative booking-management actions lack proper checks. These actions are exposed to unauthenticated users and only protected by a token issued to any anonymous visitor. This allows attackers to modify booking contents, totals, and notes without authentication.

Detection Guidance

Check if the Tripzzy WordPress plugin version is below 1.5.1. Look for unauthorized booking modifications or unusual activity in booking logs. Review network traffic for requests to booking-management endpoints without valid tokens.

Impact Analysis

Unauthenticated attackers could alter or delete booking data, manipulate financial totals, or add unauthorized notes. This could lead to financial loss, data corruption, or misuse of booking systems for malicious purposes.

Compliance Impact

This vulnerability could violate data integrity and access control requirements in GDPR and HIPAA. Unauthorized modifications to booking data may lead to non-compliance, potential fines, and loss of trust in data handling practices.

Mitigation Strategies

Update the Tripzzy WordPress plugin to version 1.5.1 or later immediately. Remove or restrict access to the token issuance endpoint if possible. Monitor bookings for unauthorized changes and audit logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87840. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart