Executive brief
A vulnerability in the WP Travel Engine plugin for WordPress allows logged-in users, even those with low-level 'subscriber' permissions, to move and rename media files on the website. By manipulating their profile settings, an attacker can relocate images or documents from the site's central library to their own profile folder. This action effectively deletes the original file from its intended location, which can break website content, disrupt operations, and cause data loss for other users.
Technical details
The WP Travel Engine plugin for WordPress fails to properly validate the source path of a user-supplied profile image before performing a file move operation. Specifically, the 'user_profile_image' parameter in the 'wp_travel_engine_save_account_details' action can be manipulated to point to an absolute server path of any file within the WordPress uploads directory. An authenticated attacker with Subscriber-level privileges can exploit this to move existing media files into their own profile image directory. Because the operation is a 'move' rather than a 'copy', the original file is deleted from its source location, leading to a loss of integrity and availability for site assets. This is classified as an External Control of File Name or Path (CWE-73). The issue is fixed in version 6.8.1.
Affected products
- WP Travel Engine WP Travel Engine < 6.8.1
Timeline
- 2026-06-16: disclosed: Initial public disclosure by WPScan
- 2026-06-16: patched: Fix released in version 6.8.1
- 2026-07-07: advisory: NVD publication date