CyberRota Analysis
AI-GeneratedThe WP Travel plugin for WordPress prior to version 11.8.1 is vulnerable as it fails to properly verify user permissions, enabling any logged-in user to access another customer's booking details, including sensitive billing information, by manipulating the booking identifier. This could lead to unauthorized exposure of personal data, posing a privacy risk. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.
Original NVD Description
The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an arbitrary booking identifier.