Input validation vulnerability in WP Travel – Best Travel Booking WordPress Plugin, Tour Management Engine 4.4.6

The WP Travel plugin for WordPress is not secure in versions up to 4.4.6. This is because it does not properly validate nonce on the save_meta_data() function. This means that unauthenticated attackers could potentially be able to save metadata for travel posts if they are able to trick a site administrator into clicking a link or performing another action.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.