CVE-2026-13145

The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an arbitrary booking identifier.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-30 06:24

Updated : 2026-07-30 16:45


NVD link : CVE-2026-13145

Mitre link : CVE-2026-13145

CVE.ORG link : CVE-2026-13145


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key