The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-9231 exposes a Local File Inclusion (LFI) vulnerability in the WP Travel Engine plugin's wte_get_template function, affecting all versions up to 6.8.0. The vulnerability allows authenticated attackers with contributor-level permissions or higher to include and execute arbitrary PHP files from the server's filesystem. This is a critical risk because it bridges the gap between low-privilege account access and arbitrary code execution—an attacker with minimal WordPress permissions can leverage this flaw to execute malicious PHP code, bypass access controls, exfiltrate sensitive data, or establish persistent backdoors. Any WordPress installation using this popular tour booking plugin with user accounts at contributor level or above is potentially at risk.
While this CVE lacks explicit MITRE ATT&CK technique mappings, Casky's 754 mapped security skills would detect the attack patterns through Claude AI's extended reasoning by identifying indicators across the execution and persistence chains. Practitioners would observe suspicious file inclusion attempts targeting template directories, unusual PHP file execution from unexpected paths, and access patterns consistent with CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). Detection would focus on monitoring the wte_get_template function calls with suspicious path parameters, template file access anomalies, and post-authentication PHP execution that deviates from normal plugin behavior—enabling security teams to catch exploitation attempts before they achieve code execution.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-9231. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation