📦 Wp Travel Engine

by Wptravelengine

🔍 What is Wp Travel Engine?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-30502

CRITICAL CVSS 9.3 Mar 29, 2024

This vulnerability allows unauthenticated attackers to perform blind SQL injection attacks on WordPress sites running the WP Travel Engine plugin. Attackers can extract sensitive database information,...

CVE-2025-5282

HIGH CVSS 7.5 Jun 13, 2025

The WP Travel Engine plugin for WordPress has an unauthenticated data deletion vulnerability. Attackers can delete arbitrary posts without authentication due to missing capability checks. All WordPres...

CVE-2025-30870

HIGH CVSS 8.1 Apr 1, 2025

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affects all WordPress sites using WP Travel Engine plug...

CVE-2025-30871

HIGH CVSS 7.5 Mar 27, 2025

This vulnerability allows attackers to include local files on the server through improper input validation in WP Travel Engine WordPress plugin. Attackers can potentially read sensitive files or execu...

CVE-2024-32798

HIGH CVSS 7.5 Jun 9, 2024

CVE-2024-32798 is a missing authorization vulnerability in WP Travel Engine WordPress plugin that allows attackers to manipulate booking prices without proper authentication. This affects all WordPres...

CVE-2024-37944

MEDIUM CVSS 6.5 Jul 20, 2024

This stored XSS vulnerability in WP Travel Engine allows attackers to inject malicious scripts into web pages that are then executed when other users view those pages. It affects all WordPress sites u...