<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WP Travel Engine – Tour Booking Plugin – Tour Operator Software (&lt;= 6.8.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wp-travel-engine--tour-booking-plugin--tour-operator-software--6.8.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 16 Aug 2026 08:24:52 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wp-travel-engine--tour-booking-plugin--tour-operator-software--6.8.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in WP Travel Engine Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-08-wp-travel-engine-auth-bypass/</link><pubDate>Sun, 16 Aug 2026 08:24:52 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-wp-travel-engine-auth-bypass/</guid><description>An authorization bypass vulnerability in the WP Travel Engine plugin for WordPress allows unauthenticated attackers to exfiltrate customer booking details by manipulating checkout form parameters.</description><content:encoded><![CDATA[<p>The WP Travel Engine plugin (up to version 6.8.4) for WordPress contains an authorization bypass vulnerability identified as CVE-2026-17087. This flaw arises because the plugin fails to verify user authorization before serving sensitive booking data. Attackers can exploit this by binding an arbitrary booking ID to their session, which triggers the application to render private customer PII - including names, email addresses, street addresses, and phone numbers - directly into the checkout form's default field values. The endpoint responsible for this data retrieval is inadequately protected by a frontend nonce, which is exposed to all visitors via the global 'wteL10n' variable on trip pages. This exposure renders the nonce ineffective as an access control mechanism, allowing unauthorized entities to perform data exfiltration at scale by iterating through booking identifiers.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the unauthorized disclosure of customer PII for users of the WP Travel Engine plugin. This impacts the privacy of customers booking travel services and potentially violates data protection regulations. The scope includes all WordPress sites running versions 6.8.4 or earlier.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the WP Travel Engine plugin to version 6.8.5 or the latest available release to patch CVE-2026-17087.</li>
<li>Review web server logs for high volumes of suspicious requests to WordPress checkout or booking endpoints originating from single IP addresses.</li>
<li>Audit WordPress plugin configurations to ensure unnecessary booking endpoints are restricted or disabled if not actively in use.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>