Back to CVE List

CVE-2026-12500

Vulnerability Description

The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the action is served to anonymous visitors).

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
WP Travel Engine

External References

Discussion (0)

Add Comment

No comments yet. Be the first!