CVE-2026-12500
Vulnerability Description
The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the action is served to anonymous visitors).
Vulnerability Details
Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
WP Travel Engine
Discussion (0)
Add Comment
No comments yet. Be the first!