{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wp-travel-engine--tour-booking-plugin--tour-operator-software--6.8.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-17087"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Travel Engine – Tour Booking Plugin – Tour Operator Software (\u003c= 6.8.4)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WP Travel Engine"],"content_html":"\u003cp\u003eThe WP Travel Engine plugin (up to version 6.8.4) for WordPress contains an authorization bypass vulnerability identified as CVE-2026-17087. This flaw arises because the plugin fails to verify user authorization before serving sensitive booking data. Attackers can exploit this by binding an arbitrary booking ID to their session, which triggers the application to render private customer PII - including names, email addresses, street addresses, and phone numbers - directly into the checkout form's default field values. The endpoint responsible for this data retrieval is inadequately protected by a frontend nonce, which is exposed to all visitors via the global 'wteL10n' variable on trip pages. This exposure renders the nonce ineffective as an access control mechanism, allowing unauthorized entities to perform data exfiltration at scale by iterating through booking identifiers.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized disclosure of customer PII for users of the WP Travel Engine plugin. This impacts the privacy of customers booking travel services and potentially violates data protection regulations. The scope includes all WordPress sites running versions 6.8.4 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WP Travel Engine plugin to version 6.8.5 or the latest available release to patch CVE-2026-17087.\u003c/li\u003e\n\u003cli\u003eReview web server logs for high volumes of suspicious requests to WordPress checkout or booking endpoints originating from single IP addresses.\u003c/li\u003e\n\u003cli\u003eAudit WordPress plugin configurations to ensure unnecessary booking endpoints are restricted or disabled if not actively in use.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T08:24:52Z","date_published":"2026-08-16T08:24:52Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wp-travel-engine-auth-bypass/","summary":"An authorization bypass vulnerability in the WP Travel Engine plugin for WordPress allows unauthenticated attackers to exfiltrate customer booking details by manipulating checkout form parameters.","title":"Authorization Bypass in WP Travel Engine Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-wp-travel-engine-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - WP Travel Engine – Tour Booking Plugin – Tour Operator Software (\u003c= 6.8.4)","version":"https://jsonfeed.org/version/1.1"}