CVE-2026-12500
EUVD-2026-5100630.07.2026, 06:24
The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the action is served to anonymous visitors).Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration