Description
The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the targeted booking on one branch of its bank-deposit handler, allowing an unauthenticated attacker who knows the target customer's email address to reset that customer's booking payment to an unpaid state and wipe its stored deposit-reconciliation data.
Published: 2026-09-09
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Payment Reset
Action: Apply Update
AI Analysis

Impact

The WP Travel plugin for WordPress includes an authorization flaw in its bank‑deposit handler. An unauthenticated user who knows the email address of a booking can send a crafted request that resets the payment status to unpaid and deletes the stored deposit‑reconciliation data, erasing payment records and potentially allowing customers to avoid being charged.

Affected Systems

The flaw affects any WordPress site that has the WP Travel plugin installed prior to version 12.0.2. Versions 12.0.1 and earlier are vulnerable. Sites using this plugin for travel reservations and booking transactions are at risk.

Risk and Exploitability

Exploitation requires no authentication; the attacker only needs to know a booking e‑mail and send a simple request to the bank‑deposit endpoint. The EPSS score of < 1% indicates low exploitation probability, while the CVSS score of 3.7 reflects moderate severity due to potential financial impact. The vulnerability is not listed in the CISA KEV catalog. Because the endpoint is reachable by unauthenticated users, operators face a moderate‑risk scenario for financial loss and record integrity.

Generated by OpenCVE AI on September 9, 2026 at 19:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP Travel plugin to version 12.0.2 or later, which enforces proper authorization checks on the bank‑deposit endpoint.
  • If an immediate update is not possible, constrain access to the bank‑deposit handler so that only authenticated users with administrative privileges can reach it.
  • Review booking logs for unexpected changes to payment status and audit the email addresses linked to unpaid bookings to detect any unauthorized resets.

Generated by OpenCVE AI on September 9, 2026 at 19:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp Travel
Wp Travel wp Travel
Vendors & Products Wordpress
Wordpress wordpress
Wp Travel
Wp Travel wp Travel

Wed, 09 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the targeted booking on one branch of its bank-deposit handler, allowing an unauthenticated attacker who knows the target customer's email address to reset that customer's booking payment to an unpaid state and wipe its stored deposit-reconciliation data.
Title WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Payment Reset
References

Subscriptions

Wordpress Wordpress
Wp Travel Wp Travel
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-09T15:41:21.925Z

Reserved: 2026-06-24T09:11:36.496Z

Link: CVE-2026-13144

cve-icon Vulnrichment

Updated: 2026-09-09T15:35:25.213Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:14.840

Modified: 2026-09-09T16:17:00.523

Link: CVE-2026-13144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T19:00:11Z

Weaknesses