Unrated severityNVD Advisory· Published Jul 30, 2026· Updated Jul 30, 2026
WP Travel < 11.8.1 - Subscriber+ Booking PII Disclosure via IDOR
CVE-2026-13145
Description
The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an arbitrary booking identifier.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/f70172b6-0a55-4b99-8b3c-8170224938bb/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.