Wptravelengine develops a WordPress plugin for travel booking and itinerary management that, despite a narrow product scope, occupies a niche within the broader WordPress ecosystem and has drawn security attention. Vulnerabilities affecting the plugin skew toward serious outcomes and frequently acquire public exploit code, clustering around web-application weakness classes including missing authorization, remote file inclusion, cross-site scripting, SQL injection, and name-resolution flaws that are characteristic of plugin-layer access-control and input-handling shortcomings. Defenders using this plugin should treat updates as a patching priority and monitor for exploitation activity; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wptravelengine over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-30502CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9. | Mar 29, 2024 | 9.8 | 42 | NO | YES |
CVE-2026-49770CRITICAL Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. | Jun 15, 2026 | 9.8 | 36 | NO | NO |
CVE-2025-30870CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows P | Apr 1, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-49078HIGH Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions. | Jun 15, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-59574MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel Engine WP Travel Engine wte-elementor-widgets allows Stored XSS.This | Sep 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-5282HIGH The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_ | Jun 13, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-30871HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows P | Mar 27, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-30504HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9. | Mar 29, 2024 | 7.2 | 21 | NO | NO |
CVE-2025-49308HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows P | Jun 6, 2025 | 7.5 | 20 | NO | NO |
CVE-2021-24680MEDIUM The WP Travel Engine WordPress plugin before 5.3.1 does not escape the Description field in the Trip Destination/Activities/Trip Type and Pricing Category pages, allowing users wit | Jan 3, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wptravelengine.
Media articles that mention a CVE ID that affects a product developed by Wptravelengine — matched by CVE ID, not by vendor name.