Unauthenticated Vulnerability in WP Travel Engine by WP Travel
CVE-2026-49078
7.5HIGH
What is CVE-2026-49078?
WP Travel Engine, a popular WordPress plugin, is affected by an unauthenticated vulnerability that allows attackers to exploit unsecured areas of the system. Users running versions 6.7.10 or earlier are particularly at risk. This vulnerability could enable unauthorized access and potential manipulation of features, ultimately jeopardizing the security of sensitive user data. It is crucial for users to update their plugins and validate their security settings to protect against potential threats.
Affected Version(s)
WP Travel Engine <= 6.7.10