What is CVE-2026-12500?
This vulnerability affects WP Travel Engine WordPress plugin versions prior to 6.8.2. The plugin fails to perform a capability check on an AJAX action, enabling unauthenticated users to overwrite a site-wide plugin option. Immediate update to the latest version is strongly recommended.
Azərbaycanca: Bu boşluq WP Travel Engine WordPress plaginin 6.8.2-dən əvvəlki versiyalarına təsir edir. Doğrulama olmaması səbəbindən autentifikasiya olunmamış istifadəçilər AJAX əməliyyatı vasitəsilə sayt genişliyində plagin parametrini yeniləyə bilər. Təhlükəsizlik üçün dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the WP Travel Engine plugin are affected by CVE-2026-12500?
This vulnerability affects WP Travel Engine WordPress plugin versions prior to 6.8.2.
What can an unauthenticated user do by exploiting CVE-2026-12500?
Unauthenticated users can overwrite a site-wide plugin option via an AJAX action.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.