AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16737

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The WP Travel Engine plugin for WordPress prior to version 6.8.5 is vulnerable due to a lack of authorization checks when handling booking identifiers in unauthenticated cart actions. This flaw allows unauthenticated attackers to access sensitive customer booking details and billing information, as well as to overwrite existing bookings. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of data exposure and unauthorized modifications.

CVE
CVE-2026-16737
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%
WordPress

Original NVD Description

The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.