Input validation vulnerability in WP Travel Engine – Tour Booking Plugin – Tour Operator Software 5.9.1

The WP Travel Engine plugin for WordPress has a security issue called Stored Cross-Site Scripting. This affects versions up to 5.9.1 because the plugin does not properly clean up or protect the information that is entered or displayed. This means that someone with contributor-level access or higher can add harmful web scripts to pages, which will run when another user views the page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.