VYPR
Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 20, 2026

WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation

CVE-2026-11868

Description

The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.