Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Thu, 30 Jul 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wptravelengine Wptravelengine wp Travel Engine |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wptravelengine Wptravelengine wp Travel Engine |
Thu, 30 Jul 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the action is served to anonymous visitors). | |
| Title | WP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-30T17:02:51.881Z
Reserved: 2026-06-17T09:09:55.183Z
Link: CVE-2026-12500
Updated: 2026-07-30T16:54:43.499Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T13:30:04Z
-
CWE-862
Missing Authorization