CVE-2026-13145
Received Received - Intake

WP Travel Plugin Unauthorized Booking Data Access Vulnerability

Vulnerability report for CVE-2026-13145, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: WPScan

Description

The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an arbitrary booking identifier.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_travel wp_travel to 11.8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Insecure Direct Object Reference (IDOR) vulnerability in the WP Travel WordPress plugin before version 11.8.1. It allows any logged-in user to access another user's booking details by manipulating a booking identifier. This includes sensitive information like billing addresses and order numbers.

Detection Guidance

To detect this vulnerability, check if your WP Travel plugin version is below 11.8.1. Log in as a user and attempt to access booking details by modifying the booking ID parameter in requests. If unauthorized data is retrieved, the vulnerability exists.

Impact Analysis

If you use the WP Travel plugin with versions prior to 11.8.1, an attacker with a valid login could access your personal booking details, including billing addresses and other sensitive data. This could lead to privacy breaches or identity theft.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to personally identifiable information (PII). Organizations may face legal penalties and reputational damage if such data breaches occur.

Mitigation Strategies

Immediately update the WP Travel plugin to version 11.8.1 or later. If updating is not possible, disable the plugin until the update is applied. Review access logs for suspicious activity related to booking ID manipulation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13145. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart