{"api_version":"v1","generated_at":"2026-10-10T03:40:00+00:00","product":{"cve_count":3,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-magepeople-wptravelly-876272fe16ad","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"WpTravelly","next_cursor":null,"observations":[{"affected":"WpTravelly: \u2264 2.3.1","affected_versions_present":true,"cve_id":"CVE-2026-62063","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62063","fixed":"Update the WordPress WpTravelly plugin to the latest available version (at least 2.3.2).","last_modified":"2026-10-01T13:17:34.846Z","patch_url":"https://patchstack.com/database/wordpress/plugin/tour-booking-manager/vulnerability/wordpress-wptravelly-plugin-2-3-1-broken-access-control-vulnerability?_s_id=cve","primary_source":"","published":"2026-10-01T12:38:26.109Z"},{"affected":"n/a \u2264 2.1.7","affected_versions_present":true,"cve_id":"CVE-2026-27089","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27089","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-16T12:41:12.254Z","patch_url":"","primary_source":"","published":"2026-06-15T20:17:34.164Z"},{"affected":"n/a \u2264 2.1.5","affected_versions_present":true,"cve_id":"CVE-2026-27331","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27331","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T10:43:19.687Z","patch_url":"","primary_source":"","published":"2026-05-26T19:29:09.970Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"Magepeople inc."}}
