CVE-2024-12272

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Dec 25, 2024
CWE ID 98

Summary

CVE-2024-12272 is a local file inclusion vulnerability affecting WP Travel Engine, a travel booking website solution built using WordPress and the Elementor plugin. Versions up to 1.3.7 are susceptible to this issue. Authenticated attackers with Contributor-level access or higher can exploit this vulnerability by including and executing arbitrary files on the server through several widgets. This can result in bypassing access controls, data theft, or code execution, posing a significant risk to websites using the affected version of WP Travel Engine and Elementor plugin.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share