Description
The WP Travel WordPress plugin before 12.0.2 does not verify that the requester is authorized to act on the booking targeted by one of its front-end payment-message handlers, allowing unauthenticated attackers to cancel the payment on any customer's booking.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Cancellation of Bookings
Action: Apply Patch
AI Analysis

Impact

The WP Travel plugin (any version lower than 12.0.2) fails to verify that a requester is authorized to act on a booking when handling front‑end payment‑message requests. This omission allows an unauthenticated user to cancel any customer's booking, resulting in loss of service availability and potential revenue loss for the site owner. The weakness is an improper access‑control flaw that can be exploited through simple HTTP requests to the payment‑message endpoint. The attacker would have no special privileges and could carry out cancellations at will, undermining the booking system’s integrity.

Affected Systems

All WordPress installations that have the WP Travel plugin installed at a version earlier than 12.0.2 are affected. The vulnerability applies to every customer booking processed by the affected plugin regardless of the user’s role, because the authorization check is missing entirely.

Risk and Exploitability

The absence of authentication or privilege verification makes this vulnerability trivial to exploit; an attacker can issue a POST to the payment‑message handler without logging in. The CVSS score of 5.3 indicates moderate severity, but the ability to cancel any customer's booking can cause significant business impact. EPSS is < 1% and the issue is not listed in the CISA KEV catalog; however, the ease of exploitation and potential revenue loss warrant immediate remediation.

Generated by OpenCVE AI on September 9, 2026 at 19:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Travel plugin to version 12.0.2 or newer so that the front‑end payment‑message handler correctly validates user authorization.
  • If the upgrade cannot be performed immediately, restrict access to the payment‑message endpoint by stripping unauthenticated requests (e.g., place a firewall rule or modify .htaccess to deny requests that lack a valid AJAX nonce).
  • Apply a generic access‑control rule that permits booking cancellation only for users with the ‘customer’ or ‘administrator’ role, ensuring the plugin’s internal checks align with WordPress capabilities.

Generated by OpenCVE AI on September 9, 2026 at 19:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp Travel
Wp Travel wp Travel
Vendors & Products Wordpress
Wordpress wordpress
Wp Travel
Wp Travel wp Travel

Wed, 09 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Travel WordPress plugin before 12.0.2 does not verify that the requester is authorized to act on the booking targeted by one of its front-end payment-message handlers, allowing unauthenticated attackers to cancel the payment on any customer's booking.
Title WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Cancellation
References

Subscriptions

Wordpress Wordpress
Wp Travel Wp Travel
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-09T15:40:22.129Z

Reserved: 2026-07-28T09:35:52.827Z

Link: CVE-2026-18042

cve-icon Vulnrichment

Updated: 2026-09-09T15:34:33.105Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:15.563

Modified: 2026-09-09T16:17:01.870

Link: CVE-2026-18042

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T18:15:06Z

Weaknesses