CVE-2026-81796
largeUnauthenticated Broken Authentication in WP Travel WordPress Plugin <= 12.0.3
CVE-2026-81796 is an unauthenticated broken authentication flaw (CWE-288) in the WP Travel travel-booking plugin for WordPress, affecting all versions up to and including 12.0.3. An attacker triggers it by sending a crafted, unauthenticated network request that reaches the plugin's authentication logic and bypasses or satisfies its credential checks without valid credentials. Successful exploitation grants access to functionality normally reserved for authenticated users, with limited confidentiality, integrity, and availability impact consistent with the CVSS 3.1 score of 7.3 (high, AV:N/AC:L/PR:N/UI:N). Any WordPress site running WP Travel 12.0.3 or earlier is affected, regardless of user role or site configuration. There is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation is known at this time.
What to do: Update WP Travel to the latest patched release (any version newer than 12.0.3) as soon as it is available, and verify the installed version under Dashboard > Plugins. Until you can update, monitor logs for unauthenticated requests hitting the plugin's endpoints and consider WAF rules restricting unauthenticated access to those routes. Since no public PoC or in-the-wild exploitation is known, patching before an exploit appears should be treated as urgent.
| WP Travel (WordPress travel booking plugin) | <= 12.0.3 (all releases up to and including 12.0.3) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-288
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.