๐Ÿ” CVE Alert

CVE-2026-13145

MEDIUM 4.3

WP Travel < 11.8.1 - Subscriber+ Booking PII Disclosure via IDOR

CVSS Score
4.3
EPSS Score
0.1%
EPSS Percentile
4th

The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an arbitrary booking identifier.

Vendor unknown
Product wp travel
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wp travel

Be the first to know when new medium vulnerabilities affecting unknown wp travel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WP Travel
0 < 11.8.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/f70172b6-0a55-4b99-8b3c-8170224938bb/

Credits

Revanth Hari Narayana Matte WPScan