PT-2026-73132 · WordPress · Wp Travel Engine

·

CVE-2026-17087

·

Published

2026-08-16

·

Updated

2026-08-16

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Travel Engine – Tour Booking Plugin – Tour Operator Software versions prior to 6.8.5
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Unauthenticated attackers can view private booking billing details, such as the customer's first name, last name, email address, street address, city, and phone number. This occurs when these details are rendered as default values in checkout form fields by binding an arbitrary booking id to the attacker's session. The endpoint relies on a frontend nonce emitted via the wteL10n global on trip pages, which only provides CSRF (Cross-Site Request Forgery) protection—a mechanism to prevent unauthorized commands from being transmitted from a user that the web application trusts—and does not restrict unauthenticated access.
Recommendations Update WP Travel Engine – Tour Booking Plugin – Tour Operator Software to version 6.8.5 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17087

Affected Products

Wp Travel Engine