← WordPress Vulnerabilities
WordPress security by component

WP Travel Engine

WP Travel Engine is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Jul 07, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: wp-travel-engine

CVE-2026-10834: WP Travel Engine: A security weakness

WP Travel Engine is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 6.8.1.

PublishedJul 07, 2026
Known safe version6.8.1
Safe version
Jul 07, 2026 CVE-2026-10834
WP Travel Engine: A security weakness
WP Travel Engine is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 6.8.1.
6.8.1
CVE4.6
NVDPending
Jun 15, 2026 CVE-2026-49770
WP Travel Engine: Code execution
WP Travel Engine is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 6.7.12.
6.8.0
CVE9.8
NVDPending
Jun 15, 2026 CVE-2026-49078
WP Travel Engine: A security weakness
WP Travel Engine is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.7.10.
6.7.11
CVE7.5
NVDPending
Oct 09, 2025 CVE-2025-7634
WP Travel Engine – Tour Booking Plugin – Tour Operator Software: Filesystem traversal
WP Travel Engine – Tour Booking Plugin – Tour Operator Software is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE9.8
NVDPending
Oct 09, 2025 CVE-2025-7526
WP Travel Engine – Tour Booking Plugin – Tour Operator Software: Code execution
WP Travel Engine – Tour Booking Plugin – Tour Operator Software is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending
Jun 13, 2025 CVE-2025-5282
WP Travel Engine – Tour Booking Plugin – Tour Operator Software: A security weakness
WP Travel Engine – Tour Booking Plugin – Tour Operator Software is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Jun 06, 2025 CVE-2025-49308
WP Travel Engine: Filesystem traversal
WP Travel Engine is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Apr 01, 2025 CVE-2025-30870
WP Travel Engine: Filesystem traversal
WP Travel Engine is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.1
NVD9.8
Mar 27, 2025 CVE-2025-30871
WP Travel Engine: Filesystem traversal
WP Travel Engine is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Nov 23, 2024 CVE-2024-10606
WP Travel Engine – Tour Booking Plugin – Tour Operator Software: A security weakness
WP Travel Engine – Tour Booking Plugin – Tour Operator Software is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jul 20, 2024 CVE-2024-37944
WP Travel Engine: Cross-site scripting
WP Travel Engine is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 09, 2024 CVE-2024-32798
WP Travel Engine: A security weakness
WP Travel Engine is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD5.3
Mar 29, 2024 CVE-2024-30504
WP Travel Engine: SQL injection
WP Travel Engine is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2
Mar 29, 2024 CVE-2024-30502
WP Travel Engine: SQL injection
WP Travel Engine is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.3
NVD9.8
Jan 03, 2022 CVE-2021-24680
WP Travel Engine: Cross-site scripting
WP Travel Engine is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4