Vulnerabilities
Vulnerable Software
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_package() function in all versions up to, and including, 6.5.1. This makes it possible for unauthenticated attackers to delete arbitrary posts.
CVSS Score
7.5
EPSS Score
0.001
Published
2025-06-13


Contact Us

Shodan ® - All rights reserved