CyberRota Analysis
AI-GeneratedThe WP Travel Engine plugin for WordPress prior to version 6.8.5 is vulnerable due to a lack of authorization checks when handling booking identifiers in unauthenticated cart actions. This flaw allows unauthenticated attackers to access sensitive customer booking details and billing information, as well as to overwrite existing bookings. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of data exposure and unauthorized modifications.
Original NVD Description
The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.