PT-2026-73132 · WordPress · Wp Travel Engine
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WP Travel Engine – Tour Booking Plugin – Tour Operator Software versions prior to 6.8.5
Description
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Unauthenticated attackers can view private booking billing details, such as the customer's first name, last name, email address, street address, city, and phone number. This occurs when these details are rendered as default values in checkout form fields by binding an arbitrary
booking id to the attacker's session. The endpoint relies on a frontend nonce emitted via the wteL10n global on trip pages, which only provides CSRF (Cross-Site Request Forgery) protection—a mechanism to prevent unauthorized commands from being transmitted from a user that the web application trusts—and does not restrict unauthenticated access.Recommendations
Update WP Travel Engine – Tour Booking Plugin – Tour Operator Software to version 6.8.5 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Travel Engine