CVE-2026-13144
Deferred Deferred - Pending Action

Unauthenticated Payment Reset in WP Travel Plugin

Vulnerability report for CVE-2026-13144, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: WPScan

Description

The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the targeted booking on one branch of its bank-deposit handler, allowing an unauthenticated attacker who knows the target customer's email address to reset that customer's booking payment to an unpaid state and wipe its stored deposit-reconciliation data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_travel wp_travel to 12.0.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WP Travel WordPress plugin before version 12.0.2. It allows an unauthenticated attacker who knows a customer's email address to reset the booking payment to an unpaid state and delete the stored deposit-reconciliation data. This happens because the plugin does not properly verify if the requester is authorized to modify the targeted booking in its bank-deposit handler.

Detection Guidance

Check if your WP Travel plugin version is below 12.0.2 by inspecting the plugin files or WordPress admin panel. Look for unauthorized booking payment resets or missing deposit-reconciliation data in your system logs.

Impact Analysis

If you use the WP Travel plugin before version 12.0.2, an attacker could reset your customers' booking payments to unpaid and delete deposit records. This could lead to financial losses, disrupted bookings, and loss of customer trust. The impact is limited to bookings where the bank-deposit handler is used.

Compliance Impact

This vulnerability could impact compliance with GDPR if personal data stored in booking records is deleted or altered without authorization. For HIPAA, if booking data includes protected health information, unauthorized changes could violate compliance. Proper data integrity and access controls are required by these regulations.

Mitigation Strategies

Update the WP Travel plugin to version 12.0.2 or later immediately. Review all recent booking payments for unauthorized changes and restore any deleted deposit-reconciliation data from backups.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13144. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart