CVE-2026-12500

EUVD-2026-51006
The WP Travel Engine  WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine  WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine  WordPress plugin before 6.8.2 option (the public nonce that gates the action is served to anonymous visitors).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%