WordPress Plugin Vulnerabilities
WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN
Description
The plugin does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid and booked state at an attacker-chosen amount.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
SPOOFING
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Revanth Hari Narayana Matte
Submitter
Revanth Hari Narayana Matte
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-13 (about 13 days ago)
Added
2026-07-13 (about 13 days ago)
Last Updated
2026-07-13 (about 13 days ago)