Junglewise Threat Intelligence

CVE-2026-18042: WP Travel arbitrary booking cancellation

CVE-2026-18042 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: Wptravel WP Travel.

Executive brief

WP Travel is a WordPress plugin for managing travel bookings and payments. The plugin fails to verify that users are authorized to modify bookings, allowing unauthenticated attackers to cancel paid bookings for any customer by making a simple web request. This undermines customer trust, disrupts payment reconciliation, and can be exploited at scale to damage the business.

Technical details

The vulnerability is a broken access control flaw (CWE-862) in WP Travel's front-end payment-message handler. The plugin does not validate that the requester is authorized to act on the booking before processing cancellation requests. An unauthenticated attacker can extract a public nonce from any trip page and send a GET request to cancel any booking by specifying a booking ID and order ID. No authentication, cookies, or user interaction is required. Attackers can enumerate sequential booking IDs to cancel multiple bookings at scale. The vulnerability is fixed in version 12.0.2.

Affected products

  • wptravel WP Travel before 12.0.2

Timeline

  • 2026-09-07: disclosed
  • 2026-09-09: patched: Fixed in version 12.0.2

References