CVE-2026-10834EPSS p14.3%
CVE-2026-10834CVE-2026-10834
Description
The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing authenticated users with subscriber-level access and above to relocate arbitrary files within the WordPress uploads directory into their own profile-image path. This removes the targeted media from its original location and can break content across the site.
Scoring
| CVSS | 4.6 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L |
| EPSS | 0.24% probability of exploitation · percentile 14.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-09 |