The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid and booked state at an attacker-chosen amount.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-290 | |
| Metrics |
cvssV3_1
|
Thu, 30 Jul 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wp Travel Wp Travel wp Travel |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wp Travel Wp Travel wp Travel |
Thu, 30 Jul 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid and booked state at an attacker-chosen amount. | |
| Title | WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-30T16:05:27.697Z
Reserved: 2026-06-24T09:11:33.920Z
Link: CVE-2026-13143
Updated: 2026-07-30T16:04:09.452Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T08:15:04Z