Local File Inclusion Vulnerability in WP Travel Engine Plugin by WordPress
CVE-2026-9231
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 September 2026
What is CVE-2026-9231?
The WP Travel Engine plugin for WordPress is susceptible to a local file inclusion vulnerability via the wte_get_template function, impacting all versions up to and including 6.8.0. This issue allows authenticated users with contributor-level access or higher to include and execute arbitrary PHP files on the server. Exploitation of this vulnerability could lead to the execution of malicious PHP code, potentially enabling attackers to bypass access controls, access sensitive data, or execute unauthorized code within the affected environment. Proper measures should be taken to update the plugin and secure the installation against such exploitation.
Affected Version(s)
WP Travel Engine β Tour Booking Plugin β Tour Operator Software 0 <= 6.8.0