The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.
We have discovered 2,259 live websites that are affected by CVE-2026-16737.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 2,259 live websites (100% of Wp Travel Engine install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 110 versions ( 99% of all versions) |
| 647 websites | |
| 185 websites | |
| 177 websites | |
| 153 websites | |
| 108 websites | |
| 90 websites | |
| 86 websites | |
| 49 websites | |
| 37 websites | |
| 35 websites |
| .com | 1,497 websites |
| .it | 58 websites |
| .org | 35 websites |
| .net | 35 websites |
| .de | 29 websites |
| .pl | 24 websites |
| .com.br | 23 websites |
| .co.uk | 22 websites |
| .nl | 21 websites |
| .ru | 18 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.com | ***,*** | ||
| *******.com | ***,*** | ||
| *********.org | ***,*** | ||
| ***************.com | ***,*** | ||
| ***********.co | ***,*** | ||
| *******************.com | ***,*** | ||
| ******.vn | *,***,*** | ||
| **********.com | *,***,*** | ||
| **************.ie | *,***,*** | ||
| *******************.es | *,***,*** |
FAQ