CVE-2026-12501: WP Travel Engine < 6.8.2 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver and Amount Verification
The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowing unauthenticated attackers to mark bookings as fully paid using a token payment made to an attacker-controlled account.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/wp-travel-engineto a version that resolves this vulnerability.Fixed in 6.8.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12501?
The severity of CVE-2026-12501 is rated as medium with a score of 5.3.
How do I fix CVE-2026-12501?
To fix CVE-2026-12501, update the WP Travel Engine plugin to version 6.8.2 or later.
What is the risk associated with CVE-2026-12501?
The risk associated with CVE-2026-12501 is potentially allowing unauthenticated attackers to mark bookings as paid without proper verification.
What versions of the WP Travel Engine plugin are affected by CVE-2026-12501?
CVE-2026-12501 affects all versions of the WP Travel Engine plugin prior to 6.8.2.
What is the main issue caused by CVE-2026-12501?
The main issue caused by CVE-2026-12501 is the lack of verification for PayPal payment notifications and the amount, allowing unauthorized payment confirmations.