CVE-2026-17087

WP Travel Engine <= 6.8.4 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'booking_id' Parameter

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view private booking billing details — including the victim customer's first name, last name, email address, street address, city, and phone number — rendered as default values in checkout form fields by binding an arbitrary booking ID to the attacker's session. The only access control on the endpoint is a frontend nonce that is publicly emitted to all visitors via the wteL10n global on trip pages, meaning it provides CSRF protection only and does not restrict unauthenticated access.


We have discovered 2,259 live websites that are affected by CVE-2026-17087.

Run a Free Instant Scan




Affected Software

Product  Wp Travel Engine
Category Wordpress Plugins
Vulnerable Domains2,259 live websites (100% of Wp Travel Engine install base)
Vulnerable Versions
  • from 0 through 6.8.4
Vulnerable Versions Count110 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Aug 16, 2026
  • Updated - Aug 17, 2026

Credits

  • Supakiad S. (m3ez) (finder)

Website Distribution by Country

Number of websites using CVE-2026-17087
United States647 websites



Germany185 websites
India177 websites
Cyprus153 websites
GB108 websites
Italy90 websites
France86 websites
Indonesia49 websites
Poland37 websites
Turkey35 websites

Website Distribution by TLD

Number of websites using CVE-2026-17087
.com1,497 websites
.it58 websites
.org35 websites
.net35 websites
.de29 websites
.pl24 websites
.com.br23 websites
.co.uk22 websites
.nl21 websites
.ru18 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-17087

Top websites that are affected by CVE-2026-17087. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.com Singapore***,***
*******.com United States***,***
*********.org United States***,***
***************.com United States***,***
***********.co United States***,***
*******************.com France***,***
******.vn Vietnam*,***,***
**********.com United States*,***,***
**************.ie Ireland*,***,***
*******************.es Spain*,***,***
See full domain list

FAQ

CVE-2026-17087 is Missing Authorization in Wp Travel Engine
A total of 2,259 websites have been identified as vulnerable to CVE-2026-17087, based on global website indexing conducted by WebTechSurvey.
The Wp Travel Engine is affected by the CVE-2026-17087 vulnerability.
Wp Travel Engine versions up to and including 6.8.4 are vulnerable to CVE-2026-17087.

References