CVE-2025-30891: WordPress WpTravelly Plugin <= 1.8.7 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpTravelly tour-booking-manager allows PHP Local File Inclusion.This issue affects WpTravelly: from n/a through <= 1.8.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30891?
CVE-2025-30891 is categorized as a critical vulnerability due to its potential for local file inclusion, which can lead to unauthorized access to sensitive files.
How do I fix CVE-2025-30891?
To fix CVE-2025-30891, update the WpTravelly plugin to version 1.8.8 or later, which addresses this vulnerability.
What software is affected by CVE-2025-30891?
CVE-2025-30891 affects MagePeople WpTravelly up to version 1.8.7 and the WordPress WpTravelly Plugin up to version 1.8.7.
What can happen if CVE-2025-30891 is exploited?
If CVE-2025-30891 is exploited, an attacker could potentially gain access to the server's file system, leading to data breaches.
Is there a patch available for CVE-2025-30891?
Yes, there is a patch available in the updated version of the WpTravelly plugin which resolves CVE-2025-30891.