Local File Inclusion Vulnerability in WP Travel Engine Plugin by WordPress
CVE-2026-9231

7.5HIGH

What is CVE-2026-9231?

The WP Travel Engine plugin for WordPress is susceptible to a local file inclusion vulnerability via the wte_get_template function, impacting all versions up to and including 6.8.0. This issue allows authenticated users with contributor-level access or higher to include and execute arbitrary PHP files on the server. Exploitation of this vulnerability could lead to the execution of malicious PHP code, potentially enabling attackers to bypass access controls, access sensitive data, or execute unauthorized code within the affected environment. Proper measures should be taken to update the plugin and secure the installation against such exploitation.

Affected Version(s)

WP Travel Engine – Tour Booking Plugin – Tour Operator Software 0 <= 6.8.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xQRx
.