WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in WP Travel Engine – Tour Booking Plugin – Tour Operator Software

WP Travel Engine is the most popular tour and travel booking WordPress plugin. Used by over 20,000 travel agency websites.

19Reported vulnerabilities
10Highest CVSS score
6.8.6Latest version
20,000+Active installs

What to do now

Update WP Travel Engine – Tour Booking Plugin – Tour Operator Software to 6.8.5 or later. 19 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 17, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-30502 Critical 10 2.2% 5.7.9 and earlier 5.8.0 March 28, 2024
CVE-2025-7634 Critical 9.8 0.8% 0 to 6.6.7 (inclusive) 6.6.8 October 9, 2025
CVE-2025-7526 Critical 9.8 0.9% 0 to 6.6.7 (inclusive) 6.6.8 October 9, 2025
CVE-2025-30870 Critical 9.8 0.8% 6.3.5 and earlier 6.3.6 March 27, 2025
CVE-2021-24680 Medium 5.4 0.6% Before 5.3.1 5.3.1 January 3, 2022
CVE-2024-30504 Critical 9.1 0.6% 5.7.9 and earlier 5.8.0 March 28, 2024
CVE-2025-30871 High 8.8 1.0% 6.3.5 and earlier 6.3.6 March 27, 2025
CVE-2025-49308 High 8.8 0.7% 6.5.1 and earlier 6.5.2 June 5, 2025
CVE-2026-49770 High 8.1 0.4% 6.7.12 and earlier 6.8.0 June 4, 2026
CVE-2026-17087 High 7.5 0.4% 0 to 6.8.4 (inclusive) 6.8.5 August 16, 2026
CVE-2025-5282 High 7.5 0.3% Before 6.5.2 6.5.2 June 13, 2025
CVE-2024-37944 Medium 6.4 0.3% 5.9.1 and earlier 5.9.2 July 10, 2024
CVE-2026-2437 Medium 6.4 0.2% 0 to 6.7.5 (inclusive) 6.7.6 April 4, 2026
CVE-2026-16737 Medium 5.3 0.2% 6.8.4 and earlier 6.8.5 August 10, 2026
CVE-2026-12501 Medium 5.3 0.2% 0 up to (but not including) 6.8.2 6.8.2 August 6, 2026
CVE-2026-12500 Medium 5.3 0.3% Before 6.8.2 6.8.2 August 5, 2026
CVE-2026-49078 Medium 5.3 0.3% 6.7.10 and earlier 6.7.11 June 5, 2026
CVE-2024-32798 Medium 5.3 0.3% 5.8.0 and earlier 5.8.1 April 22, 2024
CVE-2024-10606 Medium 4.3 0.3% Before 6.2.2 6.2.2 November 23, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.