SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-13144

LOW · CVSS 3.7 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The WP Travel plugin for WordPress prior to version 12.0.2 is vulnerable to unauthorized modification of booking payments due to inadequate verification of requesters in its bank-deposit handler. This flaw allows unauthenticated attackers, with knowledge of a target customer's email address, to reset bookings to an unpaid state and erase deposit-reconciliation data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-13144
Severity
LOW
CVSS
3.7
EPSS
0.19%
WordPress

Original NVD Description

The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the targeted booking on one branch of its bank-deposit handler, allowing an unauthenticated attacker who knows the target customer's email address to reset that customer's booking payment to an unpaid state and wipe its stored deposit-reconciliation data.