PT-2026-96684 · WordPress · Wp Travel Engine

·

CVE-2026-9231

·

Published

2026-09-22

·

Updated

2026-09-29

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Travel Engine – Tour Booking Plugin – Tour Operator Software versions prior to 6.8.1
Description The plugin contains a Local File Inclusion flaw, which occurs when an application includes a file without properly validating the input, allowing an attacker to read or execute files on the server. Authenticated users with contributor-level access or higher can exploit the wte get template() function to include and execute arbitrary .php files. This can lead to the bypass of access controls, theft of sensitive data, or remote code execution if .php files can be uploaded to the server.
Recommendations Update the plugin to version 6.8.1 or later. As a temporary mitigation, restrict access to the wte get template() function for users with contributor-level permissions.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9231

Affected Products

Wp Travel Engine