Unauthenticated Vulnerability in WP Travel Engine by WP Travel
CVE-2026-49078

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 June 2026

What is CVE-2026-49078?

WP Travel Engine, a popular WordPress plugin, is affected by an unauthenticated vulnerability that allows attackers to exploit unsecured areas of the system. Users running versions 6.7.10 or earlier are particularly at risk. This vulnerability could enable unauthorized access and potential manipulation of features, ultimately jeopardizing the security of sensitive user data. It is crucial for users to update their plugins and validate their security settings to protect against potential threats.

Affected Version(s)

WP Travel Engine <= 6.7.10

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dodoh4t | Patchstack Bug Bounty Program
.