๐Ÿ” CVE Alert

CVE-2026-16737

UNKNOWN 0.0

WP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.

Vendor unknown
Product wp travel engine
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wp travel engine

Be the first to know when new unknown vulnerabilities affecting unknown wp travel engine are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WP Travel Engine
0 < 6.8.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/1bc550f3-8b8f-42ac-aec9-7dcb7b0f7978/

Credits

Usama Arshad WPScan