← WordPress Vulnerabilities
WordPress security by component

WP Travel Pro

WP Travel Pro is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published May 29, 2026; the highest CVE/CNA score is 9.1.

Plugin slug: wp-travel-pro

CVE-2026-4290: WP Travel Pro: A security weakness

WP Travel Pro is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 10.6.0.

PublishedMay 29, 2026
Known safe version> 10.6.0
Safe version
May 29, 2026 CVE-2026-4290
WP Travel Pro: A security weakness
WP Travel Pro is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 10.6.0.
> 10.6.0
CVE9.1
NVDPending