CVE-2026-11868 | WP Travel Plugin up to 11.7.0 on WordPress Cancellation booking_cancellation authorization

SecurityVulns

A vulnerability was found in WP Travel Plugin up to 11.7.0 on WordPress. It has been declared as critical. The affected element is the function booking_cancellation of the component Cancellation. Such manipulation leads to missing authorization.

This vulnerability is referenced as CVE-2026-11868. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More