PatchSiren

WP Travel CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WP Travel CVE published 2026-07-20

CVE-2026-11868

The WP Travel WordPress plugin before 11.7.1 has a vulnerability that allows unauthenticated users to cancel arbitrary bookings on the site. This is due to a lack of capability or ownership checks on its booking cancellation action. Users of the plugin should review their installations and update to version 11.7.1 or later. The vulnerability has a medium defensive priority.

CRITICAL WP Travel CVE published 2026-06-17

CVE-2026-54808

A critical SQL injection vulnerability, known as CVE-2026-54808, has been identified in the WP Travel Gutenberg Blocks plugin. This vulnerability, with a CVSS score of 9.3, allows for blind SQL injection attacks and affects the plugin versions from n/a through 3.9.4. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the affected plugin should take immediate acti [truncated]