Description
The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.
Published: 2026-07-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WP Travel is a WordPress booking plugin. The vulnerability is that the plugin does not perform capability or ownership checks on the booking‑cancellation action, which is exposed to unauthenticated users. As a result, an attacker can cancel any existing booking on the site without permission.

Affected Systems

WordPress sites that run the WP Travel plugin version earlier than 11.7.1 and that have the cancellation endpoint publicly accessible are affected. Any installation of the plugin that has not been updated to 11.7.1 is at risk.

Risk and Exploitability

The vulnerability is scored CVSS 5.3, indicating moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require sending a web request to the cancellation endpoint, typically needing only the booking identifier. Because the endpoint is available to unauthenticated users, no additional privileges are required beyond knowledge of a valid booking ID.

Generated by OpenCVE AI on August 1, 2026 at 07:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP Travel plugin to version 11.7.1 or later, which restores proper authorization checks for booking cancellations.
  • Configure the plugin or WordPress environment to restrict the cancellation endpoint so that only authenticated or authorized users can access it, or disable the endpoint if it is not needed.
  • Set up monitoring or logging to detect unexpected or unusually frequent booking cancellations and alert administrators to investigate potential abuse.

Generated by OpenCVE AI on August 1, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp Travel
Wp Travel wp Travel
Vendors & Products Wordpress
Wordpress wordpress
Wp Travel
Wp Travel wp Travel

Mon, 20 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.
Title WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation
References

Subscriptions

Wordpress Wordpress
Wp Travel Wp Travel
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-20T13:15:28.613Z

Reserved: 2026-06-10T12:15:31.947Z

Link: CVE-2026-11868

cve-icon Vulnrichment

Updated: 2026-07-20T13:15:20.273Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T07:30:13Z

Weaknesses