CyberRota Analysis
AI-GeneratedThe WP Travel plugin for WordPress versions prior to 12.0.2 is vulnerable to unauthorized booking modifications due to inadequate verification of the requester's ownership of the booking. This flaw allows unauthenticated attackers, armed with the target customer's email address, to alter payment states and attach files to bookings, potentially leading to financial fraud or data manipulation. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an unauthenticated attacker who knows the target customer's email address to change that customer's booking payment state and attach a file to it.