ZeroHour

CVE-2026-81796

large

Unauthenticated Broken Authentication in WP Travel WordPress Plugin <= 12.0.3

CVSS 3.1
7.3 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-81796 is an unauthenticated broken authentication flaw (CWE-288) in the WP Travel travel-booking plugin for WordPress, affecting all versions up to and including 12.0.3. An attacker triggers it by sending a crafted, unauthenticated network request that reaches the plugin's authentication logic and bypasses or satisfies its credential checks without valid credentials. Successful exploitation grants access to functionality normally reserved for authenticated users, with limited confidentiality, integrity, and availability impact consistent with the CVSS 3.1 score of 7.3 (high, AV:N/AC:L/PR:N/UI:N). Any WordPress site running WP Travel 12.0.3 or earlier is affected, regardless of user role or site configuration. There is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation is known at this time.

What to do: Update WP Travel to the latest patched release (any version newer than 12.0.3) as soon as it is available, and verify the installed version under Dashboard > Plugins. Until you can update, monitor logs for unauthenticated requests hitting the plugin's endpoints and consider WAF rules restricting unauthenticated access to those routes. Since no public PoC or in-the-wild exploitation is known, patching before an exploit appears should be treated as urgent.

Affected
WP Travel (WordPress travel booking plugin)<= 12.0.3 (all releases up to and including 12.0.3)
Estimated exposure
large≈20,000+ sites (roughly 20,000+ active installs listed for WP Travel on WordPress.org; order of tens of thousands of installations) — Based on the plugin's publicly listed WordPress.org active-install count, which places the install base in the tens of thousands — largely small travel, tour, and booking operators with public-facing sites.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.

Ecosystems
WordPress
Weakness
CWE-288
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.