WP Travel Engine 5.7.9 and earlier contains a SQL injection caused by improper neutralization of special elements used in an SQL command, letting attackers execute arbitrary SQL queries, exploit requires user interaction.
id: CVE-2024-30502
info:
name: WP Travel Engine <= 5.7.9 - SQL Injection
author: Shivam Kamboj
...