Authorization Bypass Vulnerability in WP Travel Engine Plugin for WordPress
CVE-2026-17087
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
What is CVE-2026-17087?
The WP Travel Engine plugin for WordPress has a vulnerability that allows unauthorized users to bypass access controls, leading to exposure of private billing information. This issue arises from improper user authorization checks, allowing attackers to access sensitive data such as customer names, emails, and addresses by manipulating booking IDs. The plugin's existing access control mechanism, relying solely on a frontend nonce, fails to secure this endpoint against unauthenticated users, highlighting a significant risk in data privacy.
Affected Version(s)
WP Travel Engine β Tour Booking Plugin β Tour Operator Software 0 <= 6.8.4