Executive brief
WP Travel Engine, a popular WordPress plugin for managing travel bookings and tour packages, contains a security flaw in versions 6.7.10 and earlier. This vulnerability allows unauthenticated remote attackers to manipulate certain data inputs, potentially leading to unauthorized changes to site content or booking information. While the impact on data confidentiality is low, the integrity of the system's operations could be compromised.
Technical details
WP Travel Engine <= 6.7.10 is vulnerable to a flaw classified as CWE-1284 (Improper Validation of Specified Quantity in Input). The vulnerability allows an unauthenticated attacker to send specially crafted network requests to the WordPress site to manipulate data fields that lack proper validation. According to the CVSS vector, the attack has high integrity impact but no impact on confidentiality or availability. The issue is resolved in version 6.7.11.
Affected products
- WP Travel Engine WP Travel Engine <= 6.7.10
Timeline
- 2026-05-10: other: Reported by researcher dodoh4t
- 2026-06-05: patched: Version 6.7.11 released
- 2026-06-15: disclosed: CVE published