Impact
The WP Travel Engine WordPress plugin prior to 6.8.1 fails to validate the source path of a user‑supplied profile image before relocating the file. An authenticated user with subscriber‑level access or higher can submit a crafted image path that causes the plugin to move an arbitrary file within the WordPress uploads directory into the user’s own profile‑image location. The source file is removed from its original location, potentially breaking media links, page layouts, and content that relies on that file. The flaw does not permit remote code execution, privilege escalation, or direct access to system resources beyond the affected file move.
Affected Systems
Any WordPress installation that has the WP Travel Engine plugin version earlier than 6.8.1 and includes at least one subscriber‑level user is affected. Because the plugin comes from a vendor without a distinct CNA entry, the issue applies to all sites that use the vulnerable plugin, regardless of hosting environment.
Risk and Exploitability
The exploit requires authentication, so an attacker must be a substantive site user. The vulnerability’s CVSS score of 4.6 indicates medium severity, and the EPSS score of less than 1% shows a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, corroborating the limited threat profile. If used, an attacker can intentionally displace media files from their expected locations, leading to site content loss or UI breakage. The flaw does not provide code execution or broader system compromise capabilities.
OpenCVE Enrichment