Impact
The WP Travel Engine plugin does not verify that an incoming PayPal payment notification originated from the site’s merchant account, nor does it confirm that the notified amount matches the order total. As a result, an attacker can send a crafted notification and cause a booking to be marked as fully paid without having actually paid. This flaw allows unauthenticated users to manipulate payment status, potentially causing revenue loss and opening the door for fraudulent overbooking.
Affected Systems
WordPress sites using the WP Travel Engine plugin prior to version 6.8.2 are affected. The issue applies to all installations that rely on PayPal IPN for payment confirmation without additional verification steps.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited documented exploitation. Attackers can exploit this remotely by sending a forged IPN request directly to the site’s PayPal notification endpoint, so authentication is not required. The required conditions are that the site accepts IPN callbacks and the attacker can control the PayPal account used to send the notification.
OpenCVE Enrichment