PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12501 WP Travel Engine CVE debrief

The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowing unauthenticated attackers to mark bookings as fully paid using a token payment made to an attacker-controlled account.

Vendor
WP Travel Engine
Product
WP Travel Engine
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-07
Advisory published
2026-08-06
Advisory updated
2026-08-07

Who should care

WP Travel Engine plugin users, WordPress site administrators, security teams responsible for monitoring and patching vulnerabilities, and operators of e-commerce platforms using the plugin should be aware of this vulnerability. They should review and update the plugin to version 6.8.2 or later, and implement additional security controls for payment processing to prevent unauthorized booking payment manipulation.

Technical summary

The WP Travel Engine WordPress plugin, prior to version 6.8.2, lacks verification for PayPal payment notifications. This vulnerability enables attackers to mark bookings as paid using token payments to attacker-controlled accounts. The plugin's failure to validate notifications and match paid amounts to order totals creates a window for exploitation. Affected product deployments should review and update to version 6.8.2 or later, and verify PayPal payment notifications are properly validated.

Defensive priority

Medium priority given the CVSS score of 5.3 and the potential for attackers to manipulate booking payments.

Recommended defensive actions

  • Review and update WP Travel Engine plugin to version 6.8.2 or later
  • Verify PayPal payment notifications are properly validated
  • Monitor booking payments for suspicious activity
  • Implement additional security controls for payment processing
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The WP Travel Engine plugin for WordPress, before version 6.8.2, does not verify incoming PayPal payment notifications. This oversight allows unauthenticated attackers to manipulate booking payments. Evidence from the NVD and WPScan suggests that the plugin is vulnerable to unauthorized booking payment manipulation. However, details on the exact attack surface, affected versions, and potential mitigations are limited. Defenders should verify the authenticity of payment notifications and monitor booking payments for suspicious activity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:45.220Z and has not been modified since then.