What is CVE-2026-16737?
The WP Travel Engine WordPress plugin before version 6.8.5 lacks authorization checks on a booking identifier supplied in an unauthenticated cart action, allowing disclosure of any customer's booking order details. Users should immediately update the plugin to version 6.8.5 to mitigate this vulnerability.
Azərbaycanca: WP Travel Engine WordPress plaginində (6.8.5-dən əvvəlki versiyalar) autentifikasiya olunmamış istifadəçilərə təqdim edilmiş bron identifikatoru vasitəsilə digər müştərilərin sifariş detallarını görməyə imkan verən səlahiyyət yoxlaması zəifliyi aşkar edilib. Plagindən istifadə edən saytlar dərhal 6.8.5 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What does CVE-2026-16737 allow in affected versions of the WP Travel Engine plugin?
It allows unauthenticated users to view other customers' booking order details via a supplied booking identifier.
To which version must the WP Travel Engine plugin be updated to fix CVE-2026-16737?
The plugin must be immediately updated to version 6.8.5.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.