What is CVE-2026-17087?
The WP Travel Engine – Tour Booking Plugin for WordPress is vulnerable to an authorization bypass in all versions up to 6.8.4. This flaw allows unauthenticated users to perform unauthorized actions due to improper user verification. Users should immediately update to the latest patched version.
Azərbaycanca: WordPress üçün WP Travel Engine – Tour Booking Plugin proqramında 6.8.4 daxil olmaqla bütün versiyalara təsir edən authorization bypass zəifliyi aşkar edilib. Bu zəiflik autentifikasiya olunmamış istifadəçilərə müəyyən əməliyyatları icra etməyə imkan verir. Dərhal plugin-i ən son təhlükəsiz versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of the WP Travel Engine – Tour Booking Plugin are affected by CVE-2026-17087?
This authorization bypass vulnerability affects all versions of the WP Travel Engine – Tour Booking Plugin for WordPress up to and including version 6.8.4.
What can unauthenticated users do via the CVE-2026-17087 vulnerability?
The flaw allows unauthenticated users to perform certain unauthorized actions due to improper user verification.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.