Description
The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.
Published: 2026-08-12
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a caller to supply an arbitrary booking identifier to an unauthenticated cart action. Because the plugin does not perform owner or authorization checks, an attacker can read any customer's booking details and billing information, and can overwrite the booking record with their own data. The result is a breach of confidentiality, integrity, and potentially availability of sensitive booking data.

Affected Systems

WordPress installations running the WP Travel Engine plugin version 6.8.4 or earlier are affected. Any site using these older plugin releases is at risk; versions 6.8.5 and later contain the fix.

Risk and Exploitability

The CVSS score is not disclosed, but the flaw permits data exposure and modification without authentication, indicating a high impact. The EPSS score is unavailable, making it difficult to gauge current exploitation likelihood, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be a remote HTTP request to the plugin's cart endpoint, conditional only on providing a valid booking id. Because no authorization checks are performed, the exploitation is straightforward and repeatable for any booking ID.

Generated by OpenCVE AI on August 12, 2026 at 12:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WP Travel Engine to version 6.8.5 or later to apply the vendor fix
  • Configure WordPress or the plugin to require authentication for cart actions that accept booking identifiers
  • Add custom logic to verify that the booking identifier belongs to the authenticated user before allowing disclosure or modification
  • Monitor access logs for unusual booking ID requests and investigate potential abuse

Generated by OpenCVE AI on August 12, 2026 at 12:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.
Title WP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-12T06:00:15.524Z

Reserved: 2026-07-23T08:15:36.570Z

Link: CVE-2026-16737

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T06:19:10.733

Modified: 2026-08-12T06:19:10.733

Link: CVE-2026-16737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T13:00:03Z

Weaknesses

No weakness.