Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel Engine WP Travel Engine allows Stored XSS. This issue affects WP Travel Engine: from n/a through 1.4.2.
Metrics
Affected Vendors & Products
Fixes
Solution
Update the WordPress WP Travel Engine plugin to the latest available version (at least 1.4.3).
Workaround
No workaround given by the vendor.
References
History
Mon, 22 Sep 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel Engine WP Travel Engine allows Stored XSS. This issue affects WP Travel Engine: from n/a through 1.4.2. | |
Title | WordPress WP Travel Engine Plugin <= 1.4.2 - Cross Site Scripting (XSS) Vulnerability | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-09-22T18:25:55.789Z
Reserved: 2025-09-17T18:01:03.000Z
Link: CVE-2025-59574

No data.

Status : Received
Published: 2025-09-22T19:16:25.740
Modified: 2025-09-22T19:16:25.740
Link: CVE-2025-59574

No data.

No data.