View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

WP Travel Engine up to 6.8.4 exposes customer booking data

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Kirki WordPress Plugin Through 6.1.1 Exposes User Metadata CVE-2026-18347 Kirki versions through 6.1.1 let authenticated users read sensitive WordPress user data.

    • WordPress sites using the Kirki โ€“ Freeform Page Builder, Website Builder & Customizer plugin through version 6.1.1 are affected.
    • Authenticated users with custom-level access or higher can access data belonging to any WordPress user, including administrators.
    • The flaw exposes email addresses, assigned roles, registration dates, and arbitrary user metadata.
    • Attackers supply a target user ID with a user-type context to the plugin's frontend collection endpoint; CVE-2026-18347, CWE-862, CVSS 4.3. ๐Ÿ“„ Source: wordfence.com ยท ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Kirki WordPress plugin through 6.1.1 exposed authenticated path traversal Kirki versions through 6.1.1 allow authenticated arbitrary file reads.

    • Kirki โ€“ Freeform Page Builder, Website Builder & Customizer WordPress plugin users are affected.
    • All plugin versions through and including 6.1.1 are vulnerable to directory traversal.
    • Authenticated users with Editor-level access or higher can exploit the flaw.
    • The attack uses the data parameter to traverse paths and read arbitrary files. ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Bookly WordPress Plugin through 27.7 Exposed to Unauthenticated Stored XSS CVE-2026-13424 The Bookly WordPress plugin is vulnerable to unauthenticated stored cross-site scripting.

    • WordPress sites using the Bookly Online Scheduling and Appointment Booking System plugin are affected.
    • All Bookly versions up to and including 27.7 are vulnerable; CVE-2026-13424.
    • Unauthenticated attackers can inject scripts through the bookly_speed_up_update_addons AJAX action.
    • Payloads are stored in the bookly_log.details column and execute when an administrator views Diagnostics โ†’ Logs. ๐Ÿ“„ Source: wordfence.com ยท ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • WP Travel Engine up to 6.8.4 exposes customer booking data CVE-2026-16737 WP Travel Engine exposes customer booking and billing data to unauthenticated attackers.

    • WordPress sites using WP Travel Engine Tour Booking Plugin through version 6.8.4 are affected.
    • CVE-2026-16737 allows disclosure of customer booking orders and stored billing information.
    • Unauthenticated cart actions process caller-supplied booking identifiers without authorization or ownership checks.
    • Attackers can overwrite other customers' booking records with their own data. ๐Ÿ“„ Source: nvd.nist.gov ยท ๐Ÿ“Ž Coverage: radar.offseq.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Gallery by BestWebSoft through 4.7.9 Exposes Authenticated SQL Injection CVE-2026-2497 Gallery by BestWebSoft is vulnerable to authenticated SQL injection.

    • WordPress sites using Gallery by BestWebSoft are affected.
    • Versions 4.7.9 and earlier are vulnerable; CVE-2026-2497.
    • Editor-level and higher users can exploit the gallery_order{post_id} array keys.
    • Unsanitized keys are stored in post metadata and later inserted into SQL queries without prepared statements.
    • Successful exploitation can extract sensitive database information. ๐Ÿ“„ Source: wordfence.com ยท ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • WP Compress โ‰ค7.10.09 Vulnerable to CSRF Options Deletion WP Compress versions through 7.10.09 are vulnerable to CSRF-based arbitrary options deletion.

    • WordPress sites using the WP Compress โ€“ Instant Performance & Speed Optimization plugin are affected.
    • All plugin versions through and including 7.10.09 are vulnerable.
    • A cross-site request can trigger arbitrary options deletion through an authenticated WordPress session. ๐Ÿ“Ž Coverage: wordfence.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Bold Page Builder through 5.6.8 - Authenticated (Contributor+) Stored Cross-Site S... โ€” CVE ThreatInt

  • Forminator Forms through 1.55.0.2 - Insecure Direct Object Reference to Unauthenti... โ€” CVE ThreatInt

  • Infility Global through 2.15.21 - Unauthenticated Stored Cross-Site Scripting via ... โ€” CVE ThreatInt

  • Extra Product Options Builder for WooCommerce before 1.2.176 - Unauthenticated Cus... โ€” CVE ThreatInt

  • Visualizer before 4.0.7 - Contributor+ Cross-User Chart Configuration DisclosureTh... โ€” CVE ThreatInt

  • WPvivid Backup & Migration before 0.9.131 - Unauthenticated Path Traversal via sen... โ€” CVE ThreatInt

  • CatFolders Document Gallery before 2.0.7 - Unauthenticated Attachment Disclosure v... โ€” CVE ThreatInt

  • Simple JWT Login before 3.6.8 - Unauthenticated Account Takeover via Missing Googl... โ€” CVE ThreatInt

  • Masteriyo LMS before 2.3.3 - Instructor+ Stored XSS via Quiz DescriptionThe Master... โ€” CVE ThreatInt

  • Premium Packages โ€“ Sell Digital Products Securely before 7.0.7 - Subscriber+ Arbit... โ€” CVE ThreatInt

  • ECS before 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeat... โ€” CVE ThreatInt

  • All-in-One WP Migration and Backup before 7.108 - Multisite Subsite Admin+ Network... โ€” CVE ThreatInt

  • Manual Image Crop before 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite v... โ€” CVE ThreatInt

  • Free ways to learn Cyber security โ€” r/cybersecurity

  • What are the most important attack surfaces in AI applications? โ€” r/cybersecurity

  • Private companies can now Hack-Back โ€” r/cybersecurity

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check