Description
The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address to change that customer's booking payment state and attach a file to it.
Published: 2026-09-09
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Payment State Modification
Action: Patch
AI Analysis

Impact

The WP Travel WordPress plugin, versions prior to 12.0.2, contains an improper access control flaw that allows an unauthenticated attacker who knows a customer’s email address to submit a bank‑deposit slip for that customer. The flaw permits the attacker to change the booking’s payment state and attach an arbitrary file, potentially modifying financial records and inserting malicious content. This can lead to unauthorized change of payment status, and data integrity compromise of booking records, as well as the upload of harmful files.

Affected Systems

Any WordPress site that uses the WP Travel plugin with a version older than 12.0.2 is affected. The vulnerability exists in all releases before the 12.0.2 update.

Risk and Exploitability

The vulnerability can be triggered by an unauthenticated attacker who simply knows a target customer’s email address. No exploit code or public proof of concept is documented, and the EPSS score is < 1%. The CVSS score is 3.7, and the vulnerability is not listed in the CISA KEV catalog, implying that at present there is no known large‑scale exploitation. Nonetheless, the flaw allows modification of booking payment status and file uploads, so the risk remains significant if used maliciously.

Generated by OpenCVE AI on September 9, 2026 at 17:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest WP Travel plugin update (v12.0.2 or higher).
  • When an update is not immediately possible, block unauthenticated access to the bank‑deposit slip submission route, or enforce that only the owner of the booking or an administrator can modify booking payment state.
  • Review and reinforce access control logic to ensure that the requester’s booking ownership is validated before processing any payment state change or file attachment.

Generated by OpenCVE AI on September 9, 2026 at 17:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp Travel
Wp Travel wp Travel
Vendors & Products Wordpress
Wordpress wordpress
Wp Travel
Wp Travel wp Travel

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address to change that customer's booking payment state and attach a file to it.
Title WP Travel < 12.0.2 - Unauthenticated Booking Payment State Tampering via IDOR
References

Subscriptions

Wordpress Wordpress
Wp Travel Wp Travel
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-09T15:41:07.514Z

Reserved: 2026-06-24T09:11:40.802Z

Link: CVE-2026-13146

cve-icon Vulnrichment

Updated: 2026-09-09T15:35:11.781Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:14.960

Modified: 2026-09-09T16:17:00.673

Link: CVE-2026-13146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T19:45:08Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key