CVE-2026-13146
Deferred Deferred - Pending Action

Unauthenticated Booking Payment State Change in WP Travel

Vulnerability report for CVE-2026-13146, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: WPScan

Description

The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address to change that customer's booking payment state and attach a file to it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_travel wp_travel to 12.0.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the WP Travel WordPress plugin versions before 12.0.2. It allows unauthenticated attackers to change a customer's booking payment state and attach files by submitting a bank-deposit slip if they know the target's email address.

Detection Guidance

To detect this vulnerability, check if your WP Travel plugin version is prior to 12.0.2. You can do this by inspecting the plugin files or using WordPress admin panel to view the installed version. Look for unauthorized changes in booking payment states or unexpected file attachments to bookings.

Impact Analysis

An attacker could manipulate your booking payment state without authentication, potentially leading to unauthorized changes in your booking status or fraudulent attachments to your booking.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized changes to booking payment states. For GDPR, it may affect data integrity and user consent if payment details are altered without authorization. For HIPAA, if the plugin handles protected health information in bookings, unauthorized modifications could violate confidentiality requirements.

Mitigation Strategies

Immediately update the WP Travel plugin to version 12.0.2 or later. Review all booking payment states and file attachments for unauthorized changes. Monitor for suspicious activity related to bookings and restrict access to sensitive booking data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13146. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart