CVE-2026-49770
CRITICAL
NVD
CVSS Score
9.8
Severity
CRITICAL
Published
Jun 15, 2026
Vendor
unknown
Description
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.