Executive brief
WP Travel, a popular WordPress plugin for managing travel bookings, contains a security flaw that allows any registered user to view the private booking details of other customers. By simply changing a booking ID in their account dashboard, an attacker can access sensitive information such as billing addresses, order numbers, and booking dates. This could lead to the exposure of customer personally identifiable information (PII) and potential reputational damage for travel agencies using the software.
Technical details
The WP Travel plugin for WordPress fails to implement proper authorization checks on the customer account dashboard. Specifically, the dashboard component (triggered by the [wp_travel_user_account] shortcode) does not verify if a requested 'detail_id' belongs to the currently logged-in user. An attacker with a low-privileged account (Subscriber+) can obtain a publicly available nonce and then supply an arbitrary booking identifier via the 'detail_id' parameter to retrieve sensitive PII, including billing street, city, postal code, and country. This is a classic Insecure Direct Object Reference (IDOR) vulnerability (CWE-639). The issue is resolved in version 11.8.1.
Affected products
- WP Travel WP Travel < 11.8.1
Timeline
- 2026-07-13: disclosed: Publicly published by WPScan
- 2026-07-30: advisory: NVD publication date
- 2026-07-13: patched: Fixed in version 11.8.1