PatchSiren cyber security CVE debrief
CVE-2026-12501 WP Travel Engine CVE debrief
The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowing unauthenticated attackers to mark bookings as fully paid using a token payment made to an attacker-controlled account.
- Vendor
- WP Travel Engine
- Product
- WP Travel Engine
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-07
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-07
Who should care
WP Travel Engine plugin users, WordPress site administrators, security teams responsible for monitoring and patching vulnerabilities, and operators of e-commerce platforms using the plugin should be aware of this vulnerability. They should review and update the plugin to version 6.8.2 or later, and implement additional security controls for payment processing to prevent unauthorized booking payment manipulation.
Technical summary
The WP Travel Engine WordPress plugin, prior to version 6.8.2, lacks verification for PayPal payment notifications. This vulnerability enables attackers to mark bookings as paid using token payments to attacker-controlled accounts. The plugin's failure to validate notifications and match paid amounts to order totals creates a window for exploitation. Affected product deployments should review and update to version 6.8.2 or later, and verify PayPal payment notifications are properly validated.
Defensive priority
Medium priority given the CVSS score of 5.3 and the potential for attackers to manipulate booking payments.
Recommended defensive actions
- Review and update WP Travel Engine plugin to version 6.8.2 or later
- Verify PayPal payment notifications are properly validated
- Monitor booking payments for suspicious activity
- Implement additional security controls for payment processing
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The WP Travel Engine plugin for WordPress, before version 6.8.2, does not verify incoming PayPal payment notifications. This oversight allows unauthenticated attackers to manipulate booking payments. Evidence from the NVD and WPScan suggests that the plugin is vulnerable to unauthorized booking payment manipulation. However, details on the exact attack surface, affected versions, and potential mitigations are limited. Defenders should verify the authenticity of payment notifications and monitor booking payments for suspicious activity.
Official resources
-
CVE-2026-12501 CVE record
CVE.org
-
CVE-2026-12501 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:45.220Z and has not been modified since then.