CVE-2026-81796: WordPress WP Travel plugin <= 12.0.3 - Broken Authentication vulnerability
Authentication Bypass Using an Alternate Path or Channel vulnerability in WEN Solutions WP Travel wp-travel allows Password Recovery Exploitation.This issue affects WP Travel: from n/a through 12.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Travel pluginto a version that resolves this vulnerability.Fixed in 12.0.4
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges to attempt exploitation. The attack vector is network-based and requires no user interaction.
What is the potential impact?
The supplied CVSS vector indicates low confidentiality, integrity, and availability impact. Successful exploitation may affect each of those security properties to a limited extent.
Which plugin versions are affected?
WP Travel versions 12.0.3 and earlier are identified as affected.