Impact
WP Travel is a WordPress booking plugin. The vulnerability is that the plugin does not perform capability or ownership checks on the booking‑cancellation action, which is exposed to unauthenticated users. As a result, an attacker can cancel any existing booking on the site without permission.
Affected Systems
WordPress sites that run the WP Travel plugin version earlier than 11.7.1 and that have the cancellation endpoint publicly accessible are affected. Any installation of the plugin that has not been updated to 11.7.1 is at risk.
Risk and Exploitability
The vulnerability is scored CVSS 5.3, indicating moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require sending a web request to the cancellation endpoint, typically needing only the booking identifier. Because the endpoint is available to unauthenticated users, no additional privileges are required beyond knowledge of a valid booking ID.
OpenCVE Enrichment