CVE-2026-16737: CWE-639 Authorization Bypass Through User-Controlled Key in WP Travel Engine
The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.
AI Analysis
Technical Summary
The WP Travel Engine plugin for WordPress prior to version 6.8.5 fails to perform authorization or ownership verification when processing a booking identifier supplied by an unauthenticated user in one of its cart-related actions. This vulnerability (CWE-639) enables attackers without authentication to disclose sensitive booking order details and billing information of any customer. Additionally, attackers can overwrite the booking records of other customers with their own data, potentially leading to data integrity issues and privacy violations.
Potential Impact
Unauthenticated attackers can access sensitive customer booking and billing information and modify booking records of other users. This compromises confidentiality and integrity of customer data within the WP Travel Engine plugin environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor the vendor's official channels for updates and apply any released patches promptly once available. Until then, consider restricting access to the affected cart actions or implementing additional access controls if feasible.
CVE-2026-16737: CWE-639 Authorization Bypass Through User-Controlled Key in WP Travel Engine
Description
The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.
CVSS v3.1
Score 5.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The WP Travel Engine plugin for WordPress prior to version 6.8.5 fails to perform authorization or ownership verification when processing a booking identifier supplied by an unauthenticated user in one of its cart-related actions. This vulnerability (CWE-639) enables attackers without authentication to disclose sensitive booking order details and billing information of any customer. Additionally, attackers can overwrite the booking records of other customers with their own data, potentially leading to data integrity issues and privacy violations.
Potential Impact
Unauthenticated attackers can access sensitive customer booking and billing information and modify booking records of other users. This compromises confidentiality and integrity of customer data within the WP Travel Engine plugin environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor the vendor's official channels for updates and apply any released patches promptly once available. Until then, consider restricting access to the affected cart actions or implementing additional access controls if feasible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-23T08:15:36.570Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7c0ea0bf8831d539143421
Added to database: 08/12/2026, 06:11:44 UTC
Last enriched: 08/12/2026, 06:46:33 UTC
Last updated: 08/13/2026, 00:41:10 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.