PT-2026-71015 · WordPress · Wp Travel Engine

·

CVE-2026-16737

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Travel Engine versions prior to 6.8.5
Description The plugin fails to perform authorization or ownership checks when loading a booking identifier provided by the user in an unauthenticated cart action. This allows unauthenticated attackers to disclose booking order details and stored billing information of any customer. Additionally, attackers can overwrite a customer's booking record with their own data via the wte add trip to cart action.
Recommendations Update WP Travel Engine to version 6.8.5 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16737

Affected Products

Wp Travel Engine