VYPR

Wp Travel Engine

by WordPress

Source repositories

CVEs (22)

  • CVE-2026-12500HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before…

  • CVE-2026-10834MedJul 7, 2026
    risk 0.00cvss 4.6epss 0.00

    The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing authenticated users with subscriber-level access and above to relocate arbitrary files within the WordPress uploads…

Page 2 of 2