Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Wed, 09 Sep 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Wed, 09 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the targeted booking on one branch of its bank-deposit handler, allowing an unauthenticated attacker who knows the target customer's email address to reset that customer's booking payment to an unpaid state and wipe its stored deposit-reconciliation data. | |
| Title | WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Payment Reset | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-09T15:41:21.925Z
Reserved: 2026-06-24T09:11:36.496Z
Link: CVE-2026-13144
Updated: 2026-09-09T15:35:25.213Z
Status : Deferred
Published: 2026-09-09T06:17:14.840
Modified: 2026-09-09T16:17:00.523
Link: CVE-2026-13144
No data.
OpenCVE Enrichment
Updated: 2026-09-09T11:45:09Z
