Executive brief
WP Travel Engine is a WordPress plugin used by tour operators to manage bookings and trip details. A security flaw allows users with contributor-level access or higher to inject malicious scripts into website pages. These scripts execute automatically when other users, including site administrators, view the affected pages, potentially leading to unauthorized actions or data theft.
Technical details
The WP Travel Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'wte_trip_tax' shortcode. The root cause is insufficient input sanitization and output escaping on user-supplied attributes within the shortcode implementation. An authenticated attacker with contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into a post or page. These scripts will execute in the context of any user's browser who visits the compromised page. The vulnerability is addressed in version 6.7.6.
Affected products
- wptravelengine WP Travel Engine – Tour Booking Plugin – Tour Operator Software up to, and including, 6.7.5
Timeline
- 2026-04-04: disclosed
- 2026-04-04: advisory