
🚨*CVE* CVE-2026-16737 The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its… https://www.cve.org/CVERecord?id=CVE-2026-16737 ----- Traducción: CVE-2026-16737 El … http://infoflow.cloud`
Post summary
The post announces CVE-2026-16737, highlighting a lack of authorization checks in the WP Travel Engine plugin, but provides no PoC, exploit code, or patch information.

