A popular WordPress plugin called WP Travel Engine assists travel agencies in providing tools for trip planning. It allows customers to plan trips, browse travel packages, and build personalized itineraries all in one location.

The WP Travel Engine plugin, a widely used tool for booking travel on thousands of WordPress websites, has two significant vulnerabilities that security researchers have found. According to the severity scale, these vulnerabilities are 9.8 out of 10, making them extremely risky. They can launch assaults and steal personal data, endangering thousands of websites.

First vulnerability: Improper Path Restriction

The first security flaw is caused by weak file path restrictions in the plugin. Since it doesn’t properly check file paths, hackers who aren’t even logged in can rename or delete important files on the server. In some cases, deleting the right file could break the site’s setup and even let attackers run their own code remotely.

Second Vulnerability: Local File Inclusion

Poor management of a setting known as the “mode” parameter is the cause of the second defect. Without logging in, hackers can load and execute any.php file because the plugin doesn’t adequately regulate it. This may enable them to damage the website, run malicious code, or steal private data. Similar to the previous problem, it is considered a critical threat with a severity rating of 9.8.

All WP Travel Engine versions up to and including 6.6.7 are affected by these two security flaws. You must update to the most recent version of this plugin as soon as possible. The best defense against unwanted access to your website is to update it as soon as possible, since attackers can take advantage of these vulnerabilities without logging in.

Also Read: YouTube Is Bringing Back Banned Creators.