PT-2024-16401 · WordPress · Wp Travel Engine

Noah Stead

+1

·

Published

2024-11-22

·

Updated

2025-02-11

·

CVE-2024-10606

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress versions prior to 6.2.2
Description The issue is related to a missing capability check on the wpte onboard save function callback() function, allowing authenticated attackers with contributor-level access and above to modify several settings. This could have an impact such as lost revenue and page updates.
Recommendations For versions up to and including 6.2.1, update to version 6.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the wpte onboard save function callback() function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-10606

Affected Products

Wp Travel Engine