Impact
The WP Travel plugin for WordPress includes an authorization flaw in its bank‑deposit handler. An unauthenticated user who knows the email address of a booking can send a crafted request that resets the payment status to unpaid and deletes the stored deposit‑reconciliation data, erasing payment records and potentially allowing customers to avoid being charged.
Affected Systems
The flaw affects any WordPress site that has the WP Travel plugin installed prior to version 12.0.2. Versions 12.0.1 and earlier are vulnerable. Sites using this plugin for travel reservations and booking transactions are at risk.
Risk and Exploitability
Exploitation requires no authentication; the attacker only needs to know a booking e‑mail and send a simple request to the bank‑deposit endpoint. The EPSS score of < 1% indicates low exploitation probability, while the CVSS score of 3.7 reflects moderate severity due to potential financial impact. The vulnerability is not listed in the CISA KEV catalog. Because the endpoint is reachable by unauthenticated users, operators face a moderate‑risk scenario for financial loss and record integrity.
OpenCVE Enrichment