Wp Travel

WordPress plugin · wp-travel · WordPress.org ↗
0
Critical
0
High
6
Known total
0
Unfixed
Running Wp Travel on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
MEDIUM
CVSS 5.3
WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Cancellation
CVE.org
>=0, <12.0.2 v12.0.2 CVE-2026-18042 Sep 9, 2026
MEDIUM
CVSS 5.3
WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN
CVE.org
>=0, <11.8.1 v11.8.1 CVE-2026-13143 Jul 30, 2026
MEDIUM
CVSS 4.3
WP Travel < 11.8.1 - Subscriber+ Booking PII Disclosure via IDOR
CVE.org
>=0, <11.8.1 v11.8.1 CVE-2026-13145 Jul 30, 2026
MEDIUM
CVSS 5.3
WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation
CVE.org
>=0, <11.7.1 v11.7.1 CVE-2026-11868 Jul 20, 2026
LOW
CVSS 3.7
WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Payment Reset
CVE.org
>=0, <12.0.2 v12.0.2 CVE-2026-13144 Sep 9, 2026
LOW
CVSS 3.7
WP Travel < 12.0.2 - Unauthenticated Booking Payment State Tampering via IDOR
CVE.org
>=0, <12.0.2 v12.0.2 CVE-2026-13146 Sep 9, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.