Unauthenticated PHP Object Injection in WP Travel Engine by WordPress
CVE-2026-49770
9.8CRITICAL
What is CVE-2026-49770?
The WP Travel Engine plugin for WordPress is susceptible to a PHP object injection vulnerability that allows unauthenticated attackers to exploit the system. This can lead to unauthorized access and further compromise of the website's security. Users are recommended to update to the latest version to safeguard against potential attacks.
Affected Version(s)
WP Travel Engine <= 6.7.12