Impact
The WP Travel WordPress plugin, versions prior to 12.0.2, contains an improper access control flaw that allows an unauthenticated attacker who knows a customer’s email address to submit a bank‑deposit slip for that customer. The flaw permits the attacker to change the booking’s payment state and attach an arbitrary file, potentially modifying financial records and inserting malicious content. This can lead to unauthorized change of payment status, and data integrity compromise of booking records, as well as the upload of harmful files.
Affected Systems
Any WordPress site that uses the WP Travel plugin with a version older than 12.0.2 is affected. The vulnerability exists in all releases before the 12.0.2 update.
Risk and Exploitability
The vulnerability can be triggered by an unauthenticated attacker who simply knows a target customer’s email address. No exploit code or public proof of concept is documented, and the EPSS score is < 1%. The CVSS score is 3.7, and the vulnerability is not listed in the CISA KEV catalog, implying that at present there is no known large‑scale exploitation. Nonetheless, the flaw allows modification of booking payment status and file uploads, so the risk remains significant if used maliciously.
OpenCVE Enrichment