WordPress · Wp Travel Engine · CVE-2026-9231
**Name of the Vulnerable Software and Affected Versions**
WP Travel Engine – Tour Booking Plugin – Tour Operator Software versions prior to 6.8.1
**Description**
The plugin contains a Local File Inclusion flaw, which occurs when an application includes a file without properly validating the input, allowing an attacker to read or execute files on the server. Authenticated users with contributor-level access or higher can exploit the `wte get template()` function to include and execute arbitrary .php files. This can lead to the bypass of access controls, theft of sensitive data, or remote code execution if .php files can be uploaded to the server.
**Recommendations**
Update the plugin to version 6.8.1 or later.
As a temporary mitigation, restrict access to the `wte get template()` function for users with contributor-level permissions.