CVE-2026-9231: WP Travel Engine <= 6.8.0 - Authenticated (Contributor+) Local File Inclusion via 'template' Shortcode Attribute
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wtegettemplate function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated WordPress user with at least Contributor-level access can exploit it. The attack is network-accessible and does not require user interaction, but exploitation has high attack complexity.
What is required for the most serious impact?
The attacker needs to cause a PHP file available on the server to be included through the affected template handling. Code execution is possible where PHP files can be uploaded and then included; the issue can also expose sensitive data or bypass access controls.
Are installations running version 6.8.0 affected?
Yes. All versions up to and including 6.8.0 are affected.