Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 |
Wed, 09 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address to change that customer's booking payment state and attach a file to it. | |
| Title | WP Travel < 12.0.2 - Unauthenticated Booking Payment State Tampering via IDOR | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-09T06:00:04.463Z
Reserved: 2026-06-24T09:11:40.802Z
Link: CVE-2026-13146
No data.
Status : Received
Published: 2026-09-09T06:17:14.960
Modified: 2026-09-09T06:17:14.960
Link: CVE-2026-13146
No data.
OpenCVE Enrichment
Updated: 2026-09-09T11:00:08Z
