cleantalk
Vulnerabilities and Security Researches

WP Travel – Best Travel Booking WordPress Plugin, Tour Management Engine, CVE-2026-11868

CVE, Research URL

CVE-2026-11868

Published on
Jul 20, 2026
Research Description
The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.
Affected versions
max 11.7.1.
Status
vulnerable