WP Travel
- < 11.7.1
A vulnerability exists in the WP Travel WordPress plugin in versions prior to 11.7.1, where the booking cancellation action lacks proper capability and ownership checks. This flaw is accessible to unauthenticated users, enabling them to cancel any booking on the site.
Exploitation of this vulnerability allows for unauthorized cancellation of bookings, potentially disrupting business operations and customer plans.
The vulnerability can be reproduced on a clean WordPress 6.8 installation with WP Travel version 11.7.0 activated. After creating an admin-owned booking, the public nonce can be harvested from the site. This nonce is then used to send a cancellation request via the WordPress AJAX API, targeting the booking ID of the admin-owned reservation. The response will confirm the cancellation, demonstrating that the action was successfully performed by an unauthenticated user.
Users are advised to update the WP Travel WordPress plugin to version 11.7.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.