WordPress Plugin Vulnerabilities

WP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart

Description

The plugin does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.

Proof of Concept

Affects Plugins

Fixed in 6.8.5

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Usama Arshad
Submitter
Usama Arshad
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-10 (about 2 days ago)
Added
2026-08-10 (about 1 day ago)
Last Updated
2026-08-10 (about 1 day ago)

Other