CVE-2026-16737

The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-12 06:19

Updated : 2026-08-26 16:30


NVD link : CVE-2026-16737

Mitre link : CVE-2026-16737

CVE.ORG link : CVE-2026-16737


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key