What is CVE-2026-13143?
CVE-2026-13143 affects WP Travel WordPress plugin, where missing PayPal IPN verification allows unauthenticated attackers to mark bookings as paid via forged notifications. Versions before 11.8.1 are impacted. Immediate plugin update is required.
Azərbaycanca: CVE-2026-13143 WP Travel WordPress pluginində PayPal ani ödəmə bildirişi (IPN) yoxlamasının olmaması ilə bağlıdır. 11.8.1-dən əvvəlki versiyalara təsir edən bu boşluq, autentifikasiya olunmamış hücumçuya saxta bildirişlə sifarişi ödənilmiş kimi göstərməyə imkan verir. Plugin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What missing functionality in the WP Travel plugin causes the CVE-2026-13143 vulnerability?
The vulnerability is caused by missing PayPal Instant Payment Notification (IPN) verification.
What can an unauthenticated attacker achieve by exploiting CVE-2026-13143?
An attacker can mark a booking as paid by sending a forged notification.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.