Impact
The WP Travel Engine WordPress plugin before version 6.8.1 fails to validate the source path of a user‑supplied profile image before moving the file. An authenticated user with subscriber‑level access or higher can provide a crafted image path that causes the plugin to relocate an arbitrary file within the WordPress uploads directory into the user’s own profile‑image location. This removes the target media from its original location, breaking links and page layouts and resulting in content loss or corruption. The flaw does not allow remote code execution or privilege escalation, but it can cause significant content integrity and availability issues.
Affected Systems
Every WordPress site that has installed the WP Travel Engine plugin with a version older than 6.8.1 and that contains at least one user with subscriber‑level access is affected. The plugin is distributed by a vendor that does not have a distinct CNA entry, so the exposure applies broadly to all installations using the affected plugin.
Risk and Exploitability
Based on the description, the likely attack vector is a local authenticated attacker. The vulnerability requires the user to be authenticated, so only users with subscriber‑level access and above can exploit it. An attacker may craft a profile image path that points to any file inside the uploads directory; the plugin will then move that file into the user’s profile‑image folder and remove it from its original location. The EPSS score of less than one percent indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 4.6 is a medium severity rating that reflects the limited scope and lack of privilege escalation potential.
OpenCVE Enrichment