CVE-2026-49078
Description
Unauthenticated vulnerability in WP Travel Engine plugin versions <= 6.7.10 allows remote attackers to compromise websites; update to patched version.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated vulnerability in WP Travel Engine plugin versions <= 6.7.10 allows remote attackers to compromise websites; update to patched version.
Vulnerability
WP Travel Engine plugin for WordPress contains an unauthenticated vulnerability in versions up to and including 6.7.10. The exact nature of the flaw is described as "Other Vulnerability Type" in the official advisory, but it is remotely exploitable without authentication and has a CVSS score of 7.5 [1]. The vulnerability is present in the plugin's code and does not require any special configuration to reach the vulnerable code path.
Exploitation
An attacker can exploit this vulnerability without any authentication by sending specially crafted requests to a WordPress site running a vulnerable version of the WP Travel Engine plugin. The attack is conducted over the network and does not require user interaction or elevated privileges. The reference notes that vulnerabilities like this are actively used in mass-exploit campaigns targeting thousands of websites simultaneously [1].
Impact
Successful exploitation can lead to full compromise of the affected WordPress site, potentially allowing the attacker to achieve arbitrary actions such as data theft, defacement, or further propagation of attacks. The CVSS score of 7.5 indicates high severity, affecting confidentiality, integrity, and/or availability, though the exact impact is not further detailed in the available references [1].
Mitigation
The recommended mitigation is to update the WP Travel Engine plugin to a version newer than 6.7.10 as soon as possible. The Patchstack advisory urges immediate action, especially since this vulnerability is known to be targeted in mass-exploit campaigns [1]. If an update is not immediately possible, users should seek assistance from hosting providers or web developers to apply temporary measures, though no specific workaround is provided.
AI Insight generated on Jun 15, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=6.7.10+ 1 more
- (no CPE)range: <=6.7.10
- (no CPE)range: <=6.7.10
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 1, 2026 to June 7, 2026)Wordfence Blog · Jun 11, 2026