CVE-2026-16737

WP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart

The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information, and to overwrite that customer's booking record with their own data.


We have discovered 2,259 live websites that are affected by CVE-2026-16737.

Run a Free Instant Scan




Affected Software

Product  Wp Travel Engine
Category Wordpress Plugins
Vulnerable Domains2,259 live websites (100% of Wp Travel Engine install base)
Vulnerable Versions
  • from 0 through 6.8.5
Vulnerable Versions Count110 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Aug 12, 2026
  • Updated - Aug 12, 2026

Credits

  • Usama Arshad (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-16737
United States647 websites



Germany185 websites
India177 websites
Cyprus153 websites
GB108 websites
Italy90 websites
France86 websites
Indonesia49 websites
Poland37 websites
Turkey35 websites

Website Distribution by TLD

Number of websites using CVE-2026-16737
.com1,497 websites
.it58 websites
.org35 websites
.net35 websites
.de29 websites
.pl24 websites
.com.br23 websites
.co.uk22 websites
.nl21 websites
.ru18 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-16737

Top websites that are affected by CVE-2026-16737. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.com Singapore***,***
*******.com United States***,***
*********.org United States***,***
***************.com United States***,***
***********.co United States***,***
*******************.com France***,***
******.vn Vietnam*,***,***
**********.com United States*,***,***
**************.ie Ireland*,***,***
*******************.es Spain*,***,***
See full domain list

FAQ

CVE-2026-16737 is Authorization Bypass Through User-Controlled Key in Wp Travel Engine
A total of 2,259 websites have been identified as vulnerable to CVE-2026-16737, based on global website indexing conducted by WebTechSurvey.
The Wp Travel Engine is affected by the CVE-2026-16737 vulnerability.
Wp Travel Engine versions up to 6.8.5 are vulnerable to CVE-2026-16737.
CVE-2026-16737 is resolved in version 6.8.5 of Wp Travel Engine.