
WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor Security & Risk Analysis
wordpress.org/plugins/wte-elementor-widgetsWP Travel Engine – Elementor Widgets provides 20+ Elementor widgets to create travel and tour booking websites using WP Travel Engine and Elementor.
Is WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor Safe to Use in 2026?
Generally Safe
Score 97/100WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The "wte-elementor-widgets" plugin v1.5.0 presents a mixed security posture. While it demonstrates good practices in output escaping with 89% properly handled, and a lack of dangerous functions or file operations is positive, significant concerns remain. The presence of 4 AJAX handlers, with 2 lacking authentication checks, creates a substantial attack surface that could be exploited by unauthenticated users. Furthermore, the history of 2 known CVEs, including a high-severity Cross-site Scripting and a medium-severity PHP Remote File Inclusion vulnerability, indicates past weaknesses that require careful attention. Although no CVEs are currently unpatched, the nature of past vulnerabilities suggests potential for input validation and authorization flaws. The taint analysis shows 3 flows with unsanitized paths, which, while not critically severe in this analysis, could become exploitable if combined with other weaknesses. The absence of nonce checks on the unprotected AJAX endpoints is a critical oversight, leaving them vulnerable to CSRF attacks.
Overall, while the plugin has some strengths in code hygiene, the unprotected AJAX endpoints and historical vulnerabilities are significant risk factors. The lack of nonce checks on these entry points is a direct invitation for attacks. The plugin's development history with high and medium severity vulnerabilities suggests a need for more rigorous security testing and code review. Users should exercise caution and ensure that the plugin is kept up-to-date with any future security patches, and ideally, that the identified unprotected AJAX handlers are secured.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- History of high severity CVEs
- History of medium severity CVEs
- Flows with unsanitized paths
- SQL queries not fully prepared
- Limited capability checks on entry points
WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Travel Engine <= 1.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor <= 1.3.7 - Authenticated (Contributor+) Local File Inclusion
WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor Attack Surface
AJAX Handlers 4
WordPress Hooks 27
Maintenance & Trust
WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor Maintenance & Trust
Maintenance Signals
Community Trust
WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor Alternatives
WP Travel Engine – Tour Booking Plugin – Tour Operator Software
wp-travel-engine
WP Travel Engine is the most popular tour and travel booking WordPress plugin. Used by over 20,000 travel agency websites.
Travel Agency Companion – Create Tour & Travel Website Using WP Travel Engine
travel-agency-companion
It is a companion plugin for the Travel Agency theme to create travel and tour booking websites. Use it with WP Travel Engine to make the most of it.
Travel Booking Toolkit
travel-booking-toolkit
The Travel Booking Toolkit plugin works with the WP Travel Engine. It adds special widgets to the Travel Booking theme, making creating travel website …
WP Travel – Ultimate Travel Booking System, Tour Management Engine
wp-travel
WP Travel is the optimal choice among the WordPress Travel Booking Plugin and Tour Operator to Create Travel and Trekking Websites Without Coding!
Travelly – Tour & Travel Booking Manager for WooCommerce | Tour & Hotel Booking Solution
tour-booking-manager
Enhance and manage travel bookings effortlessly with WPTravelly—your complete WordPress booking solution for websites.
WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor Developer Profile
12 plugins · 41K total installs
How We Detect WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wte-elementor-widgets/assets/css/editor.css/wp-content/plugins/wte-elementor-widgets/assets/css/frontend.css/wp-content/plugins/wte-elementor-widgets/assets/js/editor.js/wp-content/plugins/wte-elementor-widgets/assets/js/frontend.js/wp-content/plugins/wte-elementor-widgets/assets/css/main.css/wp-content/plugins/wte-elementor-widgets/assets/js/main.js/wp-content/plugins/wte-elementor-widgets/assets/js/editor.js/wp-content/plugins/wte-elementor-widgets/assets/js/frontend.js/wp-content/plugins/wte-elementor-widgets/assets/js/main.jswte-elementor-widgets/assets/css/editor.css?ver=wte-elementor-widgets/assets/css/frontend.css?ver=wte-elementor-widgets/assets/js/editor.js?ver=wte-elementor-widgets/assets/js/frontend.js?ver=wte-elementor-widgets/assets/css/main.css?ver=wte-elementor-widgets/assets/js/main.js?ver=HTML / DOM Fingerprints
wte-elementor-widgetwpte-gblock-wrapperwte-d-flexwte-layout-gridwte-layout-sliderwpte-trip-list-wrapperwte-col-columns-tablet-+7 moredata-swiper-optionscardlayoutslider_arrow_positionitemsPerRowitemsPerRow_tabletitemsPerRow_mobile+17 morewp_json