Known Vulnerabilities for WP Travel Engine by Unknown
Listed below are 6 of the newest known vulnerabilities associated with "WP Travel Engine" by "Unknown".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49770 json | Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-49078 json | Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-16737 json | The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-12501 json | The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to t... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-12500 json | The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP T... | Not Provided | 2026-07-30 | 2026-07-30 |
| CVE-2026-10834 json | The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image pa... | Not Provided | 2026-07-07 | 2026-07-09 |