Junglewise Threat Intelligence

CVE-2026-11868: WP Travel WordPress plugin unauthenticated booking cancellation

CVE-2026-11868 · Severity: info · CVSS 5.3 · Published 2026-07-20

Technologies: WP Travel. Vendors: WP Travel.

Executive brief

The WP Travel plugin for WordPress, which is used to manage travel bookings and itineraries, contains a security flaw that allows anyone to cancel existing customer bookings. An attacker does not need to be logged in or have any special permissions to perform this action. This could lead to significant operational disruption, loss of revenue, and damage to a business's reputation as legitimate customer reservations are deleted without authorization.

Technical details

The WP Travel plugin fails to implement proper authorization checks (CWE-862) within its AJAX handler for booking cancellations. Specifically, the 'wp_travel_cancel_booking' action does not verify if the user requesting the cancellation is the owner of the booking or an administrator. While the action requires a security nonce, this nonce is often exposed on public-facing pages, making it accessible to unauthenticated attackers. By sending a crafted POST request to the admin-ajax.php endpoint with a valid nonce and a target 'booking_id', an attacker can change the status of any booking to 'canceled'. This vulnerability was addressed in version 11.7.1.

Affected products

  • WP Travel WP Travel < 11.7.1

Timeline

  • 2026-06-29: disclosed: Vulnerability details published by WPScan
  • 2026-07-20: advisory: CVE-2026-11868 published to NVD
  • 2026-07-20: patched: Fixed in version 11.7.1

References

Related threats