cleantalk
Vulnerabilities and Security Researches

WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor, CVE-2025-59574

CVE, Research URL

CVE-2025-59574

Published on
Sep 23, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel Engine WP Travel Engine wte-elementor-widgets allows Stored XSS.This issue affects WP Travel Engine: from n/a through <= 1.4.2.
Affected versions
max 1.4.3.
Status
vulnerable