CVE-2026-81796: WordPress WP Travel plugin <= 12.0.3 - Broken Authentication vulnerability
Published Sep 10, 2026
·Updated
Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.
Affected Software
1 affected component
WordPress WP Travel plugin<=12.0.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Travel pluginto a version that resolves this vulnerability.Fixed in 12.0.3
Event History
Sep 10, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges to attempt exploitation. The attack vector is network-based and requires no user interaction.
2
What is the potential impact?
The supplied CVSS vector indicates low confidentiality, integrity, and availability impact. Successful exploitation may affect each of those security properties to a limited extent.
3
Which plugin versions are affected?
WP Travel versions 12.0.3 and earlier are identified as affected.