CVE-2025-30871: WordPress WP Travel Engine plugin <= 6.3.5 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows PHP Local File Inclusion.This issue affects WP Travel Engine: from n/a through <= 6.3.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30871?
CVE-2025-30871 has a severity rating of high due to its potential for unauthorized file access and execution.
How do I fix CVE-2025-30871?
To fix CVE-2025-30871, update WP Travel Engine to version 6.3.6 or later, which addresses the vulnerability.
What type of vulnerability is CVE-2025-30871?
CVE-2025-30871 is classified as a PHP Remote File Inclusion vulnerability, which allows attackers to include malicious files.
Which versions of WP Travel Engine are affected by CVE-2025-30871?
CVE-2025-30871 affects all versions of WP Travel Engine from n/a up to and including 6.3.5.
What are the risks associated with CVE-2025-30871?
The risks associated with CVE-2025-30871 include remote code execution, data leakage, and server compromise.