CVE-2026-16737: WP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart
The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16737?
The severity of CVE-2026-16737 is rated at 76.
How do I fix CVE-2026-16737?
To fix CVE-2026-16737, update the WP Travel Engine plugin to version 6.8.5 or higher.
What type of vulnerability is CVE-2026-16737?
CVE-2026-16737 is an unauthenticated booking details disclosure and modification vulnerability.
Who is affected by CVE-2026-16737?
CVE-2026-16737 affects users of the WP Travel Engine plugin before version 6.8.5 on WordPress.
What can attackers do with CVE-2026-16737?
Attackers exploiting CVE-2026-16737 can disclose any customer's booking order details and stored billing information.