External risk intelligence

WP Travel Engine Plugin Arbitrary File Deletion Leading to Remote Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-7526

The vulnerability exists in a WordPress plugin designed for tour booking. Such plugins are typically installed on public-facing websites to enable customer interactions, bookings, and form submissions. Because the functionality is part of an active, internet-accessible web application, it is commonly exposed to the public internet by design to facilitate user engagement.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts WordPress sites using the WP Travel Engine plugin, a tool for managing tour bookings. It allows unauthenticated attackers to delete files on the server, potentially leading to full system compromise. The core issue lies in how the plugin handles user profile image uploads, specifically a lack of proper file path validation.

  • Attackers can delete server files without logging in.
  • It enables remote code execution for significant impact.
  • Confirm plugin relevance and check for exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could target a WordPress website using the WP Travel Engine plugin. By sending a crafted request to the plugin's profile image handling feature, the attacker could trick the server into deleting critical files. If a file like `wp-config.php` is deleted, this could lead to remote code execution.

  • No authentication required.
  • Improper file path validation allows deletion.
  • Arbitrary file deletion can lead to code execution.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could potentially delete arbitrary files on a WordPress server, which could lead to remote code execution if critical files like `wp-config.php` are targeted. This vulnerability exists within the WP Travel Engine plugin, affecting its ability to properly validate file paths during profile image updates.

  • Server files could be deleted.
  • Improper path validation allows deletion.
  • Remote code execution is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given the vulnerability in the WP Travel Engine plugin, application owners and platform teams are likely responsible for remediation. The first practical step is to identify all WordPress instances using this plugin, assess their exposure and business criticality, and then confirm the accountable owner for each instance before planning a coordinated response.

  • Application owners must be accountable.
  • Verify plugin usage and exposure.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WP Travel Engine plugin used for?

WP Travel Engine is a WordPress plugin built for tour operators. It provides functionality to manage bookings, process tour itineraries, and handle customer form submissions directly on a website, which is why it is often found on travel and tourism-related business sites.

How does CVE-2025-7526 allow for file deletion?

This vulnerability is classified as Improper Limitation of a Pathname to a Restricted Directory (CWE-22). The plugin fails to validate file paths within its profile image handling code, allowing an attacker to manipulate the system into deleting files that should remain protected.

Do I need to be logged in to trigger this vulnerability?

No. The flaw does not require authentication to exploit. An attacker can initiate the malicious request through the plugin's profile image feature without having a user account or administrative access to the WordPress dashboard.

Why should I care about this if my site is public?

Halo Surface Signal indicates this plugin is typically installed on public-facing websites to enable customer interactions. Because these sites are designed to be accessible via the internet, they are naturally exposed to external threats, making this critical flaw highly relevant for site operators.

How do I start addressing this CVE?

Your first step is to inventory your WordPress environment to identify any sites running WP Travel Engine. Once identified, determine the business importance of those specific sites and coordinate with the relevant application owners to plan your security response.

References