Vendor
high
advisory
Local File Inclusion Vulnerability in WP Travel Engine Plugin
1 rule 1 TTP 1 CVEAn unauthenticated-accessible Local File Inclusion vulnerability in the WP Travel Engine plugin (CVE-2026-9231) allows authenticated contributors to achieve remote code execution by including arbitrary PHP files.
WP Travel Engine – Tour Booking Plugin – Tour Operator Software
web-vulnerability
lfi
wordpress
1r
1t
1c
high
advisory
Authorization Bypass in WP Travel Engine Plugin
1 TTP 1 CVEAn authorization bypass vulnerability in the WP Travel Engine plugin for WordPress allows unauthenticated attackers to exfiltrate customer booking details by manipulating checkout form parameters.
WP Travel Engine – Tour Booking Plugin – Tour Operator Software
1t
1c