External risk intelligence

WP Travel Engine Local File Inclusion Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-7634

The vulnerability affects a WordPress plugin designed for tour booking and operations. Such plugins are intentionally installed on public-facing websites to enable customer interactions and reservations. Because the plugin is a web-based extension intended for internet-accessible services, it is commonly exposed to public network traffic as part of the standard deployment of the host website.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a WordPress plugin that handles tour bookings. The issue, if exploited, could allow attackers to execute arbitrary code on the server, potentially leading to unauthorized access to sensitive data or complete system compromise. The main concern at this stage is to confirm if this specific plugin is in use and assess any potential exposure.

  • Plugin flaw allows server code execution.
  • Matters due to data access and control risks.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending a specially crafted request to a vulnerable WordPress website. This request targets the WP Travel Engine plugin, specifically manipulating the 'mode' parameter. If successful, the attacker can trick the plugin into including and executing arbitrary PHP files from the server, potentially leading to unauthorized access or code execution.

  • Entry Condition: No authentication required.
  • Trigger Point: Manipulating the 'mode' parameter.
  • Resulting Risk: Arbitrary file inclusion and code execution.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could include and execute arbitrary .php files on the server when the WordPress plugin is used in supported configurations. This may allow for the execution of any PHP code, potentially bypassing access controls or obtaining sensitive data.

  • Server-side PHP files and code.
  • Inclusion of malicious PHP files.
  • Unauthorized code execution and data access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the WP Travel Engine plugin likely falls under the purview of the website's application owners or the platform team responsible for managing WordPress instances. The immediate priority is to locate all instances of the affected plugin, assess their exposure and criticality, and identify the accountable team for remediation. A risk-based approach to planning the fix is essential.

  • Ownership: Website application owners.
  • Verify first: Plugin reachability and business criticality.
  • Action: Plan and coordinate remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WP Travel Engine plugin?

WP Travel Engine is a WordPress plugin used by tour operators to manage bookings, itineraries, and customer reservations directly on their websites. Because it handles public-facing interactions like trip searching and booking, it is typically integrated into the primary web server hosting the site to process visitor input in real-time.

What does CWE-98 mean for CVE-2025-7634?

CWE-98 refers to 'Improper Control of Filename for Include/Require Statement in PHP Code.' In the context of this CVE, it means the plugin incorrectly processes input from a user, allowing an attacker to force the server to load and run files that the developers did not intend, essentially tricking the system into executing arbitrary code.

How is this vulnerability triggered?

An attacker triggers this by sending a specially crafted request to the website that manipulates the plugin's 'mode' parameter. The flaw does not require the attacker to have an account or login privileges. Simply interacting with the plugin's web interface using manipulated input is sufficient to initiate the unauthorized file inclusion.

Do I need to worry if my site is internet-facing?

Yes. According to Halo Surface Signal, because this plugin is designed for customer-facing tour operations, it is meant to be accessible to the public internet. This means the service is likely exposed to network traffic, increasing the importance of verifying your specific instance's configuration to ensure it is not reachable by unauthorized parties.

What steps should I take if I use this plugin?

First, identify all WordPress sites in your environment where WP Travel Engine is active. Determine which versions are installed to see if they fall within the affected range. Once identified, evaluate the criticality of those sites and coordinate with your web team to prepare for updates or alternative security controls to mitigate the risk of unauthorized code execution.

References