Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WP Travel Engine — Vulnerabilities & Security Advisories 10

Browse all 10 CVE security advisories affecting WP Travel Engine. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WP Travel Engine is a WordPress plugin designed for travel agencies and tour operators to create booking and travel itinerary websites. Historically, it has been vulnerable to multiple security issues including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. The plugin has accumulated 8 CVEs to date, with several critical flaws allowing unauthorized access or malicious code execution. Security researchers have identified consistent patterns in input validation and access control weaknesses. While no major public security incidents have been widely reported, the high number of CVEs indicates ongoing security challenges that require regular updates and careful implementation by users.

Top products by WP Travel Engine: WP Travel Engine
CVE ID Title CVSS Severity Published
CVE-2026-49770 WordPress WP Travel Engine plugin <= 6.7.12 - PHP Object Injection vulnerability — WP Travel Engine CWE-502 9.8 Critical 2026-06-15
CVE-2026-49078 WordPress WP Travel Engine plugin <= 6.7.10 - Other Vulnerability Type vulnerability — WP Travel Engine CWE-1284 7.5 High 2026-06-15
CVE-2025-59574 WordPress WP Travel Engine Plugin <= 1.4.2 - Cross Site Scripting (XSS) Vulnerability — WP Travel Engine CWE-79 6.5 Medium 2025-09-22
CVE-2025-49308 WordPress WP Travel Engine plugin <= 6.5.1 - Local File Inclusion Vulnerability — WP Travel Engine CWE-98 7.5 High 2025-06-06
CVE-2025-30870 WordPress WP Travel Engine plugin <= 6.3.5 - Local File Inclusion vulnerability — WP Travel Engine CWE-98 8.1 High 2025-04-01
CVE-2025-30871 WordPress WP Travel Engine plugin <= 6.3.5 - Local File Inclusion vulnerability — WP Travel Engine CWE-98 7.5 High 2025-03-27
CVE-2024-37944 WordPress WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin <= 5.9.1 - Cross Site Scripting (XSS) vulnerability — WP Travel Engine CWE-79 6.5 Medium 2024-07-20
CVE-2024-32798 WordPress WP Travel Engine plugin <= 5.8.0 - Price Manipulation vulnerability — WP Travel Engine CWE-862 7.5 High 2024-06-09
CVE-2024-30504 WordPress WP Travel Engine plugin <= 5.7.9 - SQL Injection vulnerability — WP Travel Engine CWE-89 7.6 High 2024-03-29
CVE-2024-30502 WordPress WP Travel Engine plugin <= 5.7.9 - Unauth. Blind SQL Injection vulnerability — WP Travel Engine CWE-89 9.3 Critical 2024-03-29

This page lists every published CVE security advisory associated with WP Travel Engine. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.