WP Travel Engine <= 5.7.9 - SQL Injection
CVE-2024-30502
Verified
Description
WP Travel Engine 5.7.9 and earlier contains a SQL injection caused by improper neutralization of special elements used in an SQL command, letting attackers execute arbitrary SQL queries, exploit requires user interaction.
Severity
Critical
CVSS Score
10
Exploit Probability
2%
Published Date
March 7, 2026
Template Author
shivam kamboj
CVE-2024-30502.yaml
10.0Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2024-30502
CWE ID:
cwe-89
References
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-travel-engine/wp-travel-engine-579-unauthenticated-sql-injectionhttps://patchstack.com/database/wordpress/plugin/wp-travel-engine/vulnerability/wordpress-wp-travel-engine-plugin-5-7-9-unauth-blind-sql-injection-vulnerabilityhttps://plugins.trac.wordpress.org/changeset?old_path=/wp-travel-engine/tags/5.7.9&new_path=/wp-travel-engine/tags/5.8.0&sfp_email=&sfph_mail=https://nvd.nist.gov/vuln/detail/CVE-2024-30502
Remediation Steps
Update to the latest version of WP Travel Engine.