Junglewise Threat Intelligence

CVE-2026-56059: PhysCode Travel Booking arbitrary file upload in WordPress theme

CVE-2026-56059 · Severity: critical · CVSS 9.9 · Published 2026-06-26

Executive brief

The Travel Booking theme for WordPress, used for managing travel and tourism websites, contains a critical security flaw. An attacker with a basic user account (such as a subscriber) can upload malicious files directly to the web server. This could allow them to take full control of the website, steal sensitive customer data, or disrupt business operations.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the PhysCode Travel Booking theme for WordPress in versions up to and including 2.2.5. The flaw allows an authenticated attacker with 'Subscriber' level privileges to upload dangerous file types, such as PHP scripts, to the server. Because the application fails to properly validate file extensions or content, an attacker can achieve remote code execution (RCE) and potentially gain full control over the underlying host. The vulnerability is addressed in version 2.2.6.

Affected products

  • PhysCode Travel Booking <= 2.2.5

Timeline

  • 2026-06-21: other: Reported by Jamaal ahmed
  • 2026-06-25: advisory: Patchstack advisory published
  • 2026-06-26: disclosed: NVD publication date

References