Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.58%—Wptravelengine WP Travel EngineAI22/9/202622/9/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and…
AplazadaAlta (7.5)0.69%—Wptravelengine WP Travel EngineAI16/8/202620/8/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated…
AplazadaMedia (5.3)0.32%—Wptravelengine WP Travel EngineAI12/8/202626/8/2026
The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a caller-supplied booking identifier in one of its unauthenticated cart actions, allowing unauthenticated attackers to disclose any customer's booking order details and their stored billing information,…
AplazadaMedia (5.3)0.16%—Wptravelengine WP Travel EngineAI6/8/202626/8/2026
The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowing unauthenticated attackers to mark bookings as fully paid using…
AplazadaAlta (7.5)0.36%—Wptravelengine WP Travel EngineAI30/7/202630/7/2026
The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the…
AplazadaMedia (4.6)0.24%—Wptravelengine WP Travel EngineAI7/7/20269/7/2026
The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing authenticated users with subscriber-level access and above to relocate arbitrary files within the WordPress uploads directory into their own profile-image…
AplazadaCrítica (9.8)0.56%—Wptravelengine WP Travel EngineAI15/6/202617/6/2026
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
AplazadaAlta (7.5)0.37%—Wptravelengine WP Travel EngineAI15/6/202617/6/2026
Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
AplazadaMedia (6.4)0.16%—Wptravelengine WP Travel EngineAI4/4/202624/7/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wte_trip_tax' shortcode in all versions up to, and including, 6.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
AplazadaCrítica (9.8)0.80%—Wptravelengine WP Travel EngineAI9/10/202517/6/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.6.7 via the mode parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the…
AplazadaCrítica (9.8)0.92%—Wptravelengine WP Travel EngineAI9/10/202517/6/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to insufficient file path validation in the set_user_profile_image function in all versions up to, and including, 6.6.7. This makes it possible for unauthenticated…
AplazadaMedia (6.5)0.17%—Wptravelengine WP Travel EngineAIWptravelengine WTE Elementor WidgetsAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel Engine WP Travel Engine wte-elementor-widgets allows Stored XSS.This issue affects WP Travel Engine: from n/a through <= 1.4.2.
AnalizadaAlta (7.5)0.30%—Wptravelengine WP Travel Engine13/6/202517/6/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_package() function in all versions up to, and including, 6.5.1. This makes it possible for unauthenticated attackers to delete arbitrary…
AplazadaAlta (7.5)0.74%—Wptravelengine WP Travel EngineAI6/6/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows PHP Local File Inclusion.This issue affects WP Travel Engine: from n/a through <= 6.5.1.
ModificadaCrítica (9.8)0.78%—Wptravelengine WP Travel Engine1/4/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows PHP Local File Inclusion.This issue affects WP Travel Engine: from n/a through <= 6.3.5.
ModificadaAlta (7.5)0.98%—Wptravelengine WP Travel Engine27/3/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows PHP Local File Inclusion.This issue affects WP Travel Engine: from n/a through <= 6.3.5.
AplazadaAlta (8.8)0.77%—Wptravelengine WP Travel EngineAI25/12/202417/6/2026
The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.7 via several widgets. This makes it possible for authenticated attackers, with Contributor-level access and above,…
AnalizadaMedia (4.3)0.30%—Wptravelengine WP Travel Engine23/11/202417/6/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpte_onboard_save_function_callback() function in all versions up to, and including, 6.2.1. This makes it possible for authenticated…
AnalizadaMedia (5.4)0.28%—Wptravelengine WP Travel Engine20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Travel Engine allows Stored XSS.This issue affects WP Travel Engine: from n/a through 5.9.1.
AnalizadaMedia (5.3)0.34%—Wptravelengine WP Travel Engine9/6/202417/6/2026
Missing Authorization vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.8.0.
ModificadaAlta (7.2)0.57%—Wptravelengine WP Travel Engine29/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.
ModificadaCrítica (9.8)2.2%—Wptravelengine WP Travel Engine29/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.
ModificadaMedia (5.4)0.60%—Wptravelengine WP Travel Engine3/1/202217/6/2026
The WP Travel Engine WordPress plugin before 5.3.1 does not escape the Description field in the Trip Destination/Activities/Trip Type and Pricing Category pages, allowing users with a role as low as editor to perform Stored Cross-Site Scripting attacks, even when the unfiltered_html capability is disallowed