WP Travel – Ultimate Travel Booking System, Tour Management Engine

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Access violation vulnerability in WP Travel – Ultimate Travel Booking System, Tour Management Engine 9.6.0

    Fixed

    The WP Travel plugin for WordPress has a security issue that allows unauthorized users to access it without permission. This can lead to unauthorized actions being taken by attackers.

    Read More
  • Input validation vulnerability in WP Travel – Ultimate Travel Booking System, Tour Management Engine 9.3.1

    Fixed

    The WP Travel plugin for WordPress has a security issue that allows hackers to inject malicious code into pages. This can happen on versions 9.3.1 and below, because the plugin does not properly prot...

    Read More
  • Access violation vulnerability in WP Travel – Best Travel Booking WordPress Plugin, Tour Management Engine 7.5.0

    Fixed

    The WP Travel plugin for WordPress, up to and including version 7.5.0, is vulnerable to unauthorized changes. This means that unauthenticated attackers can make changes to the plugin settings without...

    Read More
  • Input validation vulnerability in WP Travel – Best Travel Booking WordPress Plugin, Tour Management Engine 4.4.6

    Fixed

    The WP Travel plugin for WordPress is not secure in versions up to 4.4.6. This is because it does not properly validate nonce on the save_meta_data() function. This means that unauthenticated attacke...

    Read More
  • Input validation vulnerability in Freemius SDK 2.5.9 (1072 components affected)

    Fixed

    The Freemius SDK for WordPress is vulnerable to an attack known as Reflected Cross-Site Scripting. This attack is possible because of insufficient security measures in versions of the Freemius SDK up ...

    Read More
  • Input validation vulnerability in 68 different plugins

    Fixed

    Around 70 different plugins and themes had a security issue that could let someone else do something on the website without permission. The problem was that the system that was meant to stop this fro...

    Read More