CVE-2026-13143
WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN
CVSS Score
5.3
EPSS Score
0.1%
EPSS Percentile
4th
The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid and booked state at an attacker-chosen amount.
| Vendor | unknown |
| Product | wp travel |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp travel
Be the first to know when new medium vulnerabilities affecting unknown wp travel are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP Travel
0 < 11.8.1
References
Credits
Revanth Hari Narayana Matte WPScan