WP Travel Engine - Travel and Tour Booking Plugin <= 6.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via wte_trip_tax Shortcode
WP Travel Engine – Tour Booking Plugin – Tour Operator Software
Minimum safe version
6.7.6
Update to 6.7.6 or later to address 18 fixable vulnerabilities
WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Unauthenticated Local File Inclusion
WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Authenticated (Subscriber+) Arbitrary File Deletion via File Renaming
WP Travel Engine <= 6.5.1 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
CVE-2025-49308
CVE-2025-30870
CVE-2025-30871
CVE-2024-10606
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-37944
CVE-2024-32798
CVE-2024-30504
CVE-2024-30502
WordPress WP Travel Engine Plugin < 5.7.5 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress WP Travel Engine plugin <= 5.3.7 - Sensitive Information Disclosure vulnerability
WordPress WP Travel Engine plugin <= 5.3.7 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2021-24680