Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Vulnerabilities CVE-2026-13143

CVE-2026-13143

None
Open
TLP:CLEAR

WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN

AI Analysis

No AI analysis yet.

Description

The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid and booked state at an attacker-chosen amount.

Details

EPSS Score
0.22%

12.8th percentile

Confidence
90%
Published
Jul 30, 2026
Last Modified
Jul 30, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.