WP Travel WordPress Plugin Unauthenticated Arbitrary Booking Cancellation Vulnerability

Vulnerability

A vulnerability exists in the WP Travel WordPress plugin in versions prior to 11.7.1, where the booking cancellation action lacks proper capability and ownership checks. This flaw is accessible to unauthenticated users, enabling them to cancel any booking on the site.

Impact

Exploitation of this vulnerability allows for unauthorized cancellation of bookings, potentially disrupting business operations and customer plans.

Reproduction

The vulnerability can be reproduced on a clean WordPress 6.8 installation with WP Travel version 11.7.0 activated. After creating an admin-owned booking, the public nonce can be harvested from the site. This nonce is then used to send a cancellation request via the WordPress AJAX API, targeting the booking ID of the admin-owned reservation. The response will confirm the cancellation, demonstrating that the action was successfully performed by an unauthenticated user.

Remediation

Users are advised to update the WP Travel WordPress plugin to version 11.7.1 or later.

Added: Jul 20, 2026, 7:31 AM
Updated: Jul 20, 2026, 7:31 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.7
remediation
0.0
relevance
10.0
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.