The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address to change that customer's booking payment state and attach a file to it.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 09 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address to change that customer's booking payment state and attach a file to it. | |
| Title | WP Travel < 12.0.2 - Unauthenticated Booking Payment State Tampering via IDOR | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-09T06:00:04.463Z
Reserved: 2026-06-24T09:11:40.802Z
Link: CVE-2026-13146
No data.
Status : Received
Published: 2026-09-09T06:17:14.960
Modified: 2026-09-09T06:17:14.960
Link: CVE-2026-13146
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.