Local File Inclusion Vulnerability in WP Travel Engine by WordPress
CVE-2025-30871
7.5HIGH
What is CVE-2025-30871?
The WP Travel Engine, a popular plugin for WordPress, is susceptible to a local file inclusion vulnerability due to improper control of filename parameters in its PHP scripts. This flaw allows attackers to potentially leverage malicious file inclusion, which could lead to unauthorized access to sensitive files on the server. Affected versions include all releases leading up to and including version 6.3.5, highlighting the importance of keeping your plugin updated to mitigate security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Travel Engine 0 <= 6.3.5