Arbitrary File Deletion Vulnerability in WP Travel Engine Plugin for WordPress
CVE-2025-7526
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 October 2025
What is CVE-2025-7526?
The WP Travel Engine β Tour Booking Plugin for WordPress is exposed to an arbitrary file deletion vulnerability due to inadequate file path validation in its set_user_profile_image function. This flaw allows unauthenticated attackers to delete any file on the server, including critical files like wp-config.php. Such an exploit could lead to dangerous consequences, including remote code execution, posing a significant risk to affected websites.
Affected Version(s)
WP Travel Engine β Tour Booking Plugin β Tour Operator Software * <= 6.6.7