CVE-2026-13145
WP Travel < 11.8.1 - Subscriber+ Booking PII Disclosure via IDOR
CVSS Score
4.3
EPSS Score
0.1%
EPSS Percentile
4th
The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an arbitrary booking identifier.
| Vendor | unknown |
| Product | wp travel |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp travel
Be the first to know when new medium vulnerabilities affecting unknown wp travel are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP Travel
0 < 11.8.1
References
Credits
Revanth Hari Narayana Matte WPScan