SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-13146

LOW · CVSS 3.7 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The WP Travel plugin for WordPress versions prior to 12.0.2 is vulnerable to unauthorized booking modifications due to inadequate verification of the requester's ownership of the booking. This flaw allows unauthenticated attackers, armed with the target customer's email address, to alter payment states and attach files to bookings, potentially leading to financial fraud or data manipulation. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-13146
Severity
LOW
CVSS
3.7
EPSS
0.19%
WordPress

Original NVD Description

The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address to change that customer's booking payment state and attach a file to it.