CVE-2024-12272
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-12272 is a local file inclusion vulnerability affecting WP Travel Engine, a travel booking website solution built using WordPress and the Elementor plugin. Versions up to 1.3.7 are susceptible to this issue. Authenticated attackers with Contributor-level access or higher can exploit this vulnerability by including and executing arbitrary files on the server through several widgets. This can result in bypassing access controls, data theft, or code execution, posing a significant risk to websites using the affected version of WP Travel Engine and Elementor plugin.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.