Executive brief
WP Travel is a WordPress plugin for travel website management that handles user authentication and account recovery. An authentication bypass vulnerability in the password recovery mechanism allows attackers to reset passwords and gain unauthorized access to user accounts without knowing the original credentials, potentially compromising customer data and site operations.
Technical details
This is an authentication bypass vulnerability in the password recovery functionality of WP Travel plugin (CVE-2026-81796). The vulnerability allows an unauthenticated attacker to exploit an alternate path or channel in the password recovery process to reset user passwords and log in as other users. The flaw affects WP Travel versions through 12.0.3 and has been patched in version 12.0.4. This is a broken authentication vulnerability requiring no prior authentication or special privileges, exploitable over the network.
Affected products
- WEN Solutions WP Travel through 12.0.3
Timeline
- 2026-09-10: disclosed
- 2026-09-08: patched: Patch version 12.0.4 released