Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WP Travel Engine — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in WP Travel Engine, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities affecting WP Travel Engine, a WordPress plugin used for creating travel agency websites. The collection includes security advisories published between 2018 and 2023, covering a range of weakness types such as SQL injection, cross-site scripting, and authentication flaws. Users can track the vendor's historical security releases, analyze the distribution of specific weakness classes within the product, and review the complete vulnerability history for this plugin. The data is organized to support security researchers, system administrators, and developers who need to assess risk and patching priorities for sites using WP Travel Engine. No specific CVE identifiers are listed in this summary view; detailed entries are accessible through the full database.

Vendor: WP Travel Engine

CVE ID Title CVSS Severity Published
CVE-2026-16737 WP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart - - 2026-08-12
CVE-2026-12501 WP Travel Engine < 6.8.2 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver and Amount Verification 5.3 Medium 2026-08-06
CVE-2026-12500 WP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update - - 2026-07-30
CVE-2026-10834 WP Travel Engine < 6.8.1 - Subscriber+ Arbitrary Media File Move via user_profile_image - - 2026-07-07
CVE-2026-49770 WordPress WP Travel Engine plugin <= 6.7.12 - PHP Object Injection vulnerability CWE-502 9.8 Critical 2026-06-15
CVE-2026-49078 WordPress WP Travel Engine plugin <= 6.7.10 - Other Vulnerability Type vulnerability CWE-1284 7.5 High 2026-06-15
CVE-2025-59574 WordPress WP Travel Engine Plugin <= 1.4.2 - Cross Site Scripting (XSS) Vulnerability CWE-79 6.5 Medium 2025-09-22
CVE-2025-49308 WordPress WP Travel Engine plugin <= 6.5.1 - Local File Inclusion Vulnerability CWE-98 7.5 High 2025-06-06
CVE-2025-30870 WordPress WP Travel Engine plugin <= 6.3.5 - Local File Inclusion vulnerability CWE-98 8.1 High 2025-04-01
CVE-2025-30871 WordPress WP Travel Engine plugin <= 6.3.5 - Local File Inclusion vulnerability CWE-98 7.5 High 2025-03-27
CVE-2024-37944 WordPress WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin <= 5.9.1 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-07-20
CVE-2024-32798 WordPress WP Travel Engine plugin <= 5.8.0 - Price Manipulation vulnerability CWE-862 7.5 High 2024-06-09
CVE-2024-30504 WordPress WP Travel Engine plugin <= 5.7.9 - SQL Injection vulnerability CWE-89 7.6 High 2024-03-29
CVE-2024-30502 WordPress WP Travel Engine plugin <= 5.7.9 - Unauth. Blind SQL Injection vulnerability CWE-89 9.3 Critical 2024-03-29

All 14 known CVE vulnerabilities affecting WP Travel Engine with full Chinese analysis, references, and POCs where available.