SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-12500

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The WP Travel Engine plugin for WordPress versions prior to 6.8.2 is vulnerable due to a lack of capability checks on an AJAX action, enabling unauthenticated users to overwrite critical site-wide options. This could lead to unauthorized changes to plugin settings, potentially compromising site integrity and functionality. WordPress site administrators using this plugin should prioritize updating to version 6.8.2 or later to mitigate this risk.

CVE
CVE-2026-12500
Severity
HIGH
CVSS
7.5
EPSS
0.25%
WordPress

Original NVD Description

The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the action is served to anonymous visitors).