PatchSiren cyber security CVE debrief
CVE-2026-12501 WP Travel Engine CVE debrief
The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowing unauthenticated attackers to mark bookings as fully paid using a token payment made to an attacker-controlled account.
- Vendor
- WP Travel Engine
- Product
- WP Travel Engine
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-26
Who should care
WP Travel Engine plugin users, WordPress site administrators, security teams responsible for monitoring and patching vulnerabilities, and operators of e-commerce platforms using the plugin should be aware of this vulnerability. They should review and update the plugin to version 6.8.2 or later, and implement additional security controls for payment processing to prevent unauthorized booking payment manipulation.
Technical summary
The WP Travel Engine WordPress plugin, prior to version 6.8.2, lacks verification for PayPal payment notifications. This vulnerability enables attackers to mark bookings as paid using token payments to attacker-controlled accounts. The plugin's failure to validate notifications and match paid amounts to order totals creates a window for exploitation. Affected product deployments should review and update to version 6.8.2 or later, and verify PayPal payment notifications are properly validated.
Defensive priority
Medium priority given the CVSS score of 5.3 and the potential for attackers to manipulate booking payments.
Recommended defensive actions
- Review and update WP Travel Engine plugin to version 6.8.2 or later
- Verify PayPal payment notifications are properly validated
- Monitor booking payments for suspicious activity
- Implement additional security controls for payment processing
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The WP Travel Engine plugin for WordPress, before version 6.8.2, does not verify incoming PayPal payment notifications. This oversight allows unauthenticated attackers to manipulate booking payments. Evidence from the NVD and WPScan suggests that the plugin is vulnerable to unauthorized booking payment manipulation. However, details on the exact attack surface, affected versions, and potential mitigations are limited. Defenders should verify the authenticity of payment notifications and monitor booking payments for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12501 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12501
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12501 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12501
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/3959ea5e-9670-4087-9506-44ba95c6a462/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.