CVE-2025-5282: WP Travel Engine <= 6.5.1 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deletepackage() function in all versions up to, and including, 6.5.1. This makes it possible for unauthenticated attackers to delete arbitrary posts.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5282?
CVE-2025-5282 is classified as a critical severity vulnerability due to its potential for unauthorized data deletion.
How do I fix CVE-2025-5282?
To fix CVE-2025-5282, update the WP Travel Engine plugin to version 6.5.2 or later.
What versions are affected by CVE-2025-5282?
CVE-2025-5282 affects all versions of the WP Travel Engine plugin up to and including version 6.5.1.
What impact does CVE-2025-5282 have on my website?
CVE-2025-5282 allows unauthorized users to delete packages, potentially resulting in data loss.
Who is vulnerable to CVE-2025-5282?
Any user running the WP Travel Engine plugin version 6.5.1 or earlier on their WordPress site is vulnerable to CVE-2025-5282.