PatchSiren

WP Travel Engine CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WP Travel Engine CVE published 2026-08-06

CVE-2026-12501

The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowing unauthenticated attackers to mark bookings as fully paid using a token payment made to an attacker-controlled account.

MEDIUM WP Travel Engine CVE published 2026-07-07

CVE-2026-10834

The WP Travel Engine WordPress plugin before version 6.8.1 has a vulnerability that allows authenticated users with subscriber-level access and above to relocate arbitrary files within the WordPress uploads directory into their own profile-image path. This can break content across the site by removing the targeted media from its original location. The vulnerability is caused by a lack of proper validation [truncated]

CRITICAL WP Travel Engine CVE published 2026-06-15

CVE-2026-49770

CVE-2026-49770 is a critical vulnerability in the WP Travel Engine plugin for WordPress. The vulnerability, which has a CVSS score of 9.8, allows unauthenticated PHP object injection and affects plugin versions <= 6.7.12. The vulnerability was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-49770) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-49770).