CVE-2026-18042 | WP Travel Plugin up to 12.0.1 on WordPress Payment Message authorization
A vulnerability has been found in WP Travel Plugin up to 12.0.1 on WordPress and classified as critical. Impacted is an unknown function of the component Payment Message Handler. This manipulation causes missing authorization.
This vulnerability appears as CVE-2026-18042. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.VulDB Recent EntriesRead More