WP Travel
Unknown- Software type
- —
- Catalog vulnerabilities
- 6
Severity across 6 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 6 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 6 vulnerability records affecting WP Travel.
Among the 6 records analyzed by CyStack, 0 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-18042WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Cancellation | Exploitation statusPublic exploit | FixYes | Published09/09/2026 | SeverityMedium |
CVE-2026-13146WP Travel < 12.0.2 - Unauthenticated Booking Payment State Tampering via IDOR | Exploitation statusPublic exploit | FixYes | Published09/09/2026 | SeverityLow |
CVE-2026-13144WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Payment Reset | Exploitation statusPublic exploit | FixYes | Published09/09/2026 | SeverityLow |
CVE-2026-13145WP Travel < 11.8.1 - Subscriber+ Booking PII Disclosure via IDOR | Exploitation statusPublic exploit | FixYes | Published07/30/2026 | SeverityMedium |
CVE-2026-13143WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN | Exploitation statusPublic exploit | FixYes | Published07/30/2026 | SeverityMedium |
CVE-2026-11868WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation | Exploitation statusPublic exploit | FixYes | Published07/20/2026 | SeverityMedium |