PT-2026-96684 · WordPress · Wp Travel Engine
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP Travel Engine – Tour Booking Plugin – Tour Operator Software versions prior to 6.8.1
Description
The plugin contains a Local File Inclusion flaw, which occurs when an application includes a file without properly validating the input, allowing an attacker to read or execute files on the server. Authenticated users with contributor-level access or higher can exploit the
wte get template() function to include and execute arbitrary .php files. This can lead to the bypass of access controls, theft of sensitive data, or remote code execution if .php files can be uploaded to the server.Recommendations
Update the plugin to version 6.8.1 or later.
As a temporary mitigation, restrict access to the
wte get template() function for users with contributor-level permissions.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Travel Engine