Known vulnerabilities in Travelly – Tour & Travel Booking Manager for WooCommerce
Travelly is a WordPress tour and travel booking plugin for WooCommerce. Sell tours, manage hotel bookings, and accept payments online.
9Reported vulnerabilities
8.8Highest CVSS score
2.2.0Latest version
1,000+Active installs
What to do now
Update Travelly – Tour & Travel Booking Manager for WooCommerce to 2.1.8 or later.
9 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-30892 | High | 0.7% | 1.8.7 and earlier | 1.8.8 |
April 1, 2025 |
| CVE-2025-30891 | High | 0.7% | 1.8.7 and earlier | 1.8.8 |
March 27, 2025 |
| CVE-2024-43212 | Medium | 0.6% | 1.7.7 and earlier | 1.7.8 |
August 9, 2024 |
| CVE-2026-27089 | Medium | 0.3% | 2.1.7 and earlier | 2.1.8 |
June 1, 2026 |
| CVE-2025-22737 | Medium | 0.3% | 1.8.5 and earlier | 1.8.6 |
January 14, 2025 |
| CVE-2024-0434 | Medium | 0.4% | 0 to 1.7.1 (inclusive) | 1.7.2 |
May 29, 2024 |
| CVE-2026-27331 | Medium | 0.2% | 2.1.5 and earlier | 2.1.6 |
May 26, 2026 |
| CVE-2026-39565 | Medium | 0.2% | 2.1.7 and earlier | 2.1.8 |
March 21, 2026 |
| CVE-2024-32450 | Medium | 0.2% | 1.6.0 and earlier | 1.6.1 |
April 12, 2024 |