CVE-2026-13143
Received Received - Intake

WP Travel Plugin PayPal IPN Verification Bypass

Vulnerability report for CVE-2026-13143, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: WPScan

Description

The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid and booked state at an attacker-chosen amount.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_travel wp_travel to 11.8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WP Travel WordPress plugin versions before 11.8.1. It allows unauthenticated attackers to forge PayPal payment notifications, bypassing verification. By sending a fake IPN POST request with attacker-controlled values like transaction ID or amount, they can change pending bookings to paid status without proper authentication.

Detection Guidance

Check if your WP Travel plugin version is below 11.8.1. Inspect server logs for unexpected PayPal IPN POST requests with forged booking IDs or amounts. Look for bookings marked as paid without corresponding payment records.

Impact Analysis

Attackers could manipulate bookings to appear paid without actual payment, leading to financial losses for businesses using the plugin. It may also allow unauthorized bookings to be confirmed, disrupting normal operations and potentially causing disputes or chargebacks.

Mitigation Strategies

Update the WP Travel plugin to version 11.8.1 or later immediately. Review all recent bookings for unauthorized changes to paid status or amounts. Implement additional server-side validation for PayPal IPN responses.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13143. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart