Shinetheme Traveler WordPress Theme SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in the Shinetheme Traveler WordPress theme, affecting versions prior to 3.2.2. This vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized database access and information theft.

Impact

Exploitation of this vulnerability allows for direct interaction with the database, which could be used to steal information.

Remediation

Users are advised to update to version 3.2.2 or later. Patchstack has issued a virtual patch to block attacks until the update is applied.

Added: Jul 16, 2025, 3:57 PM
Updated: Jul 16, 2025, 3:57 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.