Plugin Vulnerability Hub
Plugin 13 known issues Latest disclosed Apr 03, 2026

WP Travel Engine – Tour Booking Plugin – Tour Operator Software Vulnerabilities

Review known vulnerability records for the WordPress plugin WP Travel Engine – Tour Booking Plugin – Tour Operator Software (`wp-travel-engine`), including severity, CVE references, affected versions, and patch status.

Known Records
13
High or Critical
8
Linked CVEs
13
Last Updated
Apr 04, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for WP Travel Engine – Tour Booking Plugin – Tour Operator Software so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
13 records include a published patch path.
Severity Mix
5 critical and 3 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for WP Travel Engine – Tour Booking Plugin – Tour Operator Software

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-2437
WP Travel Engine - Travel and Tour Booking Plugin <= 6.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via wte_trip_tax Shortcode

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wte_trip_tax' shortcode in all versions up to, and including, 6.7.5 due to insufficient input sanitization and output escaping o...

Published
Apr 03, 2026
Patched Release
6.7.6
Affected Versions
Versions up to 6.7.5
Next Step
Update to 6.7.6 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-7634
WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Unauthenticated Local File Inclusion

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.6.7 via the mode parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary...

Published
Oct 08, 2025
Patched Release
6.6.8
Affected Versions
Versions up to 6.6.7
Next Step
Update to 6.6.8 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-7526
WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Authenticated (Subscriber+) Arbitrary File Deletion via File Renaming

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to insufficient file path validation in the set_user_profile_image function in all versions up to, and including, 6.6.7. This makes...

Published
Oct 08, 2025
Patched Release
6.6.8
Affected Versions
Versions up to 6.6.7
Next Step
Update to 6.6.8 or newer if supported.
Plugin High Patched: Yes CVE-2025-5282
WP Travel Engine <= 6.5.1 - Missing Authorization to Unauthenticated Arbitrary Post Deletion

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_package() function in all versions up to, and including, 6.5.1. This makes it possible for unauthent...

Published
Jun 12, 2025
Patched Release
6.5.2
Affected Versions
Versions up to 6.5.1
Next Step
Update to 6.5.2 or newer if supported.
Plugin High Patched: Yes CVE-2025-49308
WP Travel Engine <= 6.5.1 - Authenticated (Contributor+) Local File Inclusion

The WP Travel Engine plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.5.1. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the...

Published
Jun 05, 2025
Patched Release
6.5.2
Affected Versions
Versions up to 6.5.1
Next Step
Update to 6.5.2 or newer if supported.
Plugin High Patched: Yes CVE-2025-30871
WP Travel Engine <= 6.3.5 - Authenticated (Contributor+) Local File Inclusion

The WP Travel Engine plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.5. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the...

Published
Mar 27, 2025
Patched Release
6.3.6
Affected Versions
Versions up to 6.3.5
Next Step
Update to 6.3.6 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-30870
WP Travel Engine <= 6.3.5 - Unauthenticated Local File Inclusion

The WP Travel Engine plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.5. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those file...

Published
Mar 27, 2025
Patched Release
6.3.6
Affected Versions
Versions up to 6.3.5
Next Step
Update to 6.3.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-10606
WP Travel Engine <= 6.2.1 - Missing Authorization to Authenticated (Contributor+) Plugin Settings Update

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpte_onboard_save_function_callback() function in all versions up to, and including, 6.2.1. This ma...

Published
Nov 22, 2024
Patched Release
6.2.2
Affected Versions
Versions up to 6.2.1
Next Step
Update to 6.2.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-37944
WP Travel Engine <= 5.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP Travel Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,...

Published
Jul 10, 2024
Patched Release
5.9.2
Affected Versions
Versions up to 5.9.1
Next Step
Update to 5.9.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-32798
WP Travel Engine <= 5.8.0 - Unauthenticated Price Manipulation

The WP Travel Engine – Best Travel Booking WordPress Plugin plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 5.8.0. This is due to the plugin not properly validating a price. This makes it possible for unauthenticated attackers to man...

Published
Apr 22, 2024
Patched Release
5.8.1
Affected Versions
Versions up to 5.8.0
Next Step
Update to 5.8.1 or newer if supported.
Plugin Critical Patched: Yes CVE-2024-30502
WP Travel Engine <= 5.7.9 - Unauthenticated SQL Injection

The WP Travel Engine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated at...

Published
Mar 28, 2024
Patched Release
5.8.0
Affected Versions
Versions up to 5.7.9
Next Step
Update to 5.8.0 or newer if supported.
Plugin Critical Patched: Yes CVE-2024-30504
WP Travel Engine <= 5.7.9 - Authenticated (Administrator+) SQL Injection

The WP Travel Engine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...

Published
Mar 28, 2024
Patched Release
5.8.0
Affected Versions
Versions up to 5.7.9
Next Step
Update to 5.8.0 or newer if supported.