CVE-2026-16737
Deferred Deferred - Pending Action

Unauthenticated Information Disclosure in WP Travel Engine

Vulnerability report for CVE-2026-16737, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-26

Assigner: WPScan

Description

The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-26
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_travel_engine wp_travel_engine to 6.8.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the WP Travel Engine WordPress plugin before version 6.8.5 allows unauthenticated attackers to access and modify booking details by exploiting missing authorization checks in an unauthenticated cart action. Attackers can view any customer's booking order details and billing information or overwrite a customer's booking record with their own data.

Detection Guidance

To detect this vulnerability, check if your WP Travel Engine plugin version is below 6.8.5. You can use commands like 'wp plugin list' in WordPress CLI or inspect the plugin version via the WordPress admin panel.

Impact Analysis

This vulnerability can lead to unauthorized access to sensitive customer data such as booking details and billing information. Attackers could also manipulate booking records, potentially causing data breaches or financial loss for customers and reputational damage for businesses using the plugin.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access and potential exposure of personal and financial data. It could result in non-compliance penalties, legal consequences, and loss of customer trust due to inadequate data protection measures.

Mitigation Strategies

Immediately update the WP Travel Engine plugin to version 6.8.5 or later. Remove any unauthorized bookings if detected and review billing information for tampering.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16737. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart