CVE-2026-12501
Received Received - Intake

WP Travel Engine Plugin Payment Verification Bypass

Vulnerability report for CVE-2026-12501, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WPScan

Description

The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowing unauthenticated attackers to mark bookings as fully paid using a token payment made to an attacker-controlled account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_travel_engine wp_travel_engine to 6.8.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WP Travel Engine WordPress plugin before version 6.8.2. It allows unauthenticated attackers to manipulate payment notifications from PayPal. The plugin fails to verify if a payment notification was sent to the site's configured merchant account or if the paid amount matches the order total. Attackers can exploit this by using a token payment to an attacker-controlled account to mark bookings as fully paid.

Detection Guidance

Check if your WP Travel Engine plugin version is below 6.8.2. Inspect PayPal payment notifications for mismatches between paid amounts and order totals. Review booking status logs for unauthorized changes marked as paid without proper verification.

Impact Analysis

This vulnerability could allow attackers to trick the system into marking fake or unauthorized bookings as paid without actually receiving payment. This could lead to financial losses, unauthorized reservations, or misuse of services. Users relying on this plugin for booking payments may face incorrect booking statuses and potential service disruptions.

Mitigation Strategies

Update the WP Travel Engine plugin to version 6.8.2 or later immediately. Verify PayPal payment notifications match configured merchant accounts and order totals before marking bookings as paid. Implement additional validation checks for payment processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12501. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart