
WP Travel Gutenberg Blocks Security & Risk Analysis
wordpress.org/plugins/wp-travel-blocksWP Travel Gutenberg Blocks is the easiest, most flexible way to display your Trips using the Gutenberg blocks.
Is WP Travel Gutenberg Blocks Safe to Use in 2026?
Generally Safe
Score 93/100WP Travel Gutenberg Blocks has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-travel-blocks" v3.9.4 plugin exhibits a mixed security posture. On the positive side, the code analysis shows no dangerous functions, all SQL queries utilize prepared statements, and file operations and external HTTP requests are absent. The use of nonces is present, and the majority of output is properly escaped, indicating some good security practices. However, significant concerns arise from the attack surface. Three out of five total entry points, including all three REST API routes, lack permission callbacks, leaving them unprotected and potentially exploitable by unauthenticated users.
The vulnerability history is a major red flag. While there are currently no unpatched vulnerabilities, the plugin has a history of four known CVEs, including one high-severity and three medium-severity issues. The common vulnerability types, such as PHP Remote File Inclusion and Cross-Site Scripting, suggest a recurring pattern of issues related to input validation and handling of file paths. The last vulnerability being in late 2025 is concerning as it implies recent past issues.
In conclusion, while "wp-travel-blocks" v3.9.4 demonstrates some strengths in its coding practices, the substantial number of unprotected entry points and the historical pattern of significant vulnerabilities, particularly in areas like file inclusion and XSS, present a notable risk. The absence of capability checks on REST API routes and the presence of multiple unprotected AJAX handlers are critical areas for immediate attention.
Key Concerns
- 3 unprotected REST API routes
- 2 unprotected AJAX handlers
- 1 High severity CVE historically
- 3 Medium severity CVEs historically
- 73% output escaping is not 100%
- Missing capability checks
WP Travel Gutenberg Blocks Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
WP Travel Gutenberg Blocks <= 3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Travel Gutenberg Blocks <= 3.9.0 - Unauthenticated Local File Inclusion
WP Travel Gutenberg Blocks <= 3.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Travel Gutenberg Blocks <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Travel Gutenberg Blocks Code Analysis
Output Escaping
WP Travel Gutenberg Blocks Attack Surface
AJAX Handlers 2
REST API Routes 3
WordPress Hooks 13
Maintenance & Trust
WP Travel Gutenberg Blocks Maintenance & Trust
Maintenance Signals
Community Trust
WP Travel Gutenberg Blocks Alternatives
WP Travel Engine – Tour Booking Plugin – Tour Operator Software
wp-travel-engine
WP Travel Engine is the most popular tour and travel booking WordPress plugin. Used by over 20,000 travel agency websites.
WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor
wte-elementor-widgets
WP Travel Engine – Elementor Widgets provides 20+ Elementor widgets to create travel and tour booking websites using WP Travel Engine and Elementor.
Travel Agency Companion – Create Tour & Travel Website Using WP Travel Engine
travel-agency-companion
It is a companion plugin for the Travel Agency theme to create travel and tour booking websites. Use it with WP Travel Engine to make the most of it.
Travel Booking Toolkit
travel-booking-toolkit
The Travel Booking Toolkit plugin works with the WP Travel Engine. It adds special widgets to the Travel Booking theme, making creating travel website …
WP Travel – Ultimate Travel Booking System, Tour Management Engine
wp-travel
WP Travel is the optimal choice among the WordPress Travel Booking Plugin and Tour Operator to Create Travel and Trekking Websites Without Coding!
WP Travel Gutenberg Blocks Developer Profile
32 plugins · 47K total installs
How We Detect WP Travel Gutenberg Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-travel-blocks/assets/css/editor-style.css/wp-content/plugins/wp-travel-blocks/assets/css/magnific-popup.css/wp-content/plugins/wp-travel-blocks/assets/css/splide.css/wp-content/plugins/wp-travel-blocks/assets/css/frontend.css/wp-content/plugins/wp-travel-blocks/assets/js/theia-sticky-sidebar.js/wp-content/plugins/wp-travel-blocks/assets/js/magnific-popup.js/wp-content/plugins/wp-travel-blocks/assets/js/matchheight.js/wp-content/plugins/wp-travel-blocks/assets/js/splide.js+19 morehttps://cdn.jsdelivr.net/npm/swiper@11/swiper-bundle.min.jsHTML / DOM Fingerprints
wp-travel-blocks-frontenddata-trip-iddata-trip-titleblock_trip_ajaxplaceHolderImage