Medium 6.5 Unfixed
2026-02-20≤ 1.2.2
CVE-2025-68042
Minimum safe version
1.1.17
Update to 1.1.17 or later to address 5 fixable vulnerabilities
CVE-2025-68042
Travelpayouts <= 1.1.12 - Cross-Site Request Forgery to Settings Import
WordPress Travelpayouts Plugin < 1.1.14 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-0337
Travelpayouts < 1.0.17 - CSRF Bypass due to Outdated Redux Framework
Travelpayouts <= 1.0.16 - Cross-Site Request Forgery