Known Vulnerabilities for Wp Travel Engine by Wptravelengine
Listed below are 5 of the newest known vulnerabilities associated with "Wp Travel Engine" by "Wptravelengine".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49770 json | Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-49078 json | Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-10834 json | The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image pa... | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2025-30871 json | Not Provided | 2025-03-27 | 2026-04-23 | |
| CVE-2025-30870 json | Not Provided | 2025-04-01 | 2026-04-23 | |
| CVE-2024-30504 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This i... | Not Provided | 2024-03-29 | 2026-04-28 |
| CVE-2024-30502 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This i... | Not Provided | 2024-03-29 | 2026-04-28 |
| CVE-2021-24680 json | The WP Travel Engine WordPress plugin before 5.3.1 does not escape the Description field in the Trip Destination/Activities/T... | 5.4 - MEDIUM | 2022-01-03 | 2022-01-07 |