CVE-2025-30870: WordPress WP Travel Engine plugin <= 6.3.5 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows PHP Local File Inclusion.This issue affects WP Travel Engine: from n/a through <= 6.3.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30870?
CVE-2025-30870 is considered a high severity vulnerability due to its potential for remote file inclusion.
How do I fix CVE-2025-30870?
To fix CVE-2025-30870, update the WP Travel Engine plugin to the latest version beyond 6.3.5.
Which versions of WP Travel Engine are affected by CVE-2025-30870?
CVE-2025-30870 affects WP Travel Engine versions from n/a through 6.3.5.
What type of vulnerability is CVE-2025-30870?
CVE-2025-30870 is a PHP Remote File Inclusion vulnerability that allows improper control of filenames.
What are the risks associated with CVE-2025-30870?
The risks of CVE-2025-30870 include potential unauthorized access to sensitive files and executing arbitrary code on the server.