Impact
The WP Travel plugin (any version lower than 12.0.2) fails to verify that a requester is authorized to act on a booking when handling front‑end payment‑message requests. This omission allows an unauthenticated user to cancel any customer's booking, resulting in loss of service availability and potential revenue loss for the site owner. The weakness is an improper access‑control flaw that can be exploited through simple HTTP requests to the payment‑message endpoint. The attacker would have no special privileges and could carry out cancellations at will, undermining the booking system’s integrity.
Affected Systems
All WordPress installations that have the WP Travel plugin installed at a version earlier than 12.0.2 are affected. The vulnerability applies to every customer booking processed by the affected plugin regardless of the user’s role, because the authorization check is missing entirely.
Risk and Exploitability
The absence of authentication or privilege verification makes this vulnerability trivial to exploit; an attacker can issue a POST to the payment‑message handler without logging in. The CVSS score of 5.3 indicates moderate severity, but the ability to cancel any customer's booking can cause significant business impact. EPSS is < 1% and the issue is not listed in the CISA KEV catalog; however, the ease of exploitation and potential revenue loss warrant immediate remediation.
OpenCVE Enrichment