CVE-2026-13143

WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN

The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid and booked state at an attacker-chosen amount.


We have discovered 856 live websites that are affected by CVE-2026-13143.

Run a Free Instant Scan




Affected Software

Product  Wp Travel
Category Wordpress Plugins
Vulnerable Domains856 live websites (100% of Wp Travel install base)
Vulnerable Versions
  • from 0 through 11.8.1
Vulnerable Versions Count79 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-290 Authentication Bypass by Spoofing



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • Revanth Hari Narayana Matte (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-13143
United States241 websites



Vietnam134 websites
Germany67 websites
India45 websites
Italy34 websites
France32 websites
GB29 websites
Romania18 websites
Cyprus15 websites
Indonesia15 websites

Website Distribution by TLD

Number of websites using CVE-2026-13143
.com470 websites
.org40 websites
.net40 websites
.it28 websites
.de21 websites
.co.uk12 websites
.com.br11 websites
.info9 websites
.ru8 websites
.nl7 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-13143

Top websites that are affected by CVE-2026-13143. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.***.au Australia***,***
*********.org United States***,***
*****************.com France*,***,***
***********.com Cyprus*,***,***
************.org United States*,***,***
**************.com Poland*,***,***
******************.com Germany*,***,***
*************.com United States*,***,***
******.it Italy*,***,***
*************.com United States*,***,***
See full domain list

FAQ

CVE-2026-13143 is Authentication Bypass by Spoofing in Wp Travel
A total of 856 websites have been identified as vulnerable to CVE-2026-13143, based on global website indexing conducted by WebTechSurvey.
The Wp Travel is affected by the CVE-2026-13143 vulnerability.
Wp Travel versions up to 11.8.1 are vulnerable to CVE-2026-13143.
CVE-2026-13143 is resolved in version 11.8.1 of Wp Travel.