cvedb.io
CVE-2026-13145
UNKNOWN · CVSS n/a
EPSS exploitation probability: 0%
Published 2026-07-30T06:24:58.953 · Last modified 2026-07-30T06:24:58.953

Summary

The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an arbitrary booking identifier.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.