The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the targeted booking on one branch of its bank-deposit handler, allowing an unauthenticated attacker who knows the target customer's email address to reset that customer's booking payment to an unpaid state and wipe its stored deposit-reconciliation data.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 09 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the targeted booking on one branch of its bank-deposit handler, allowing an unauthenticated attacker who knows the target customer's email address to reset that customer's booking payment to an unpaid state and wipe its stored deposit-reconciliation data. | |
| Title | WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Payment Reset | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-09T06:00:04.289Z
Reserved: 2026-06-24T09:11:36.496Z
Link: CVE-2026-13144
No data.
Status : Received
Published: 2026-09-09T06:17:14.840
Modified: 2026-09-09T06:17:14.840
Link: CVE-2026-13144
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.