Impact
WordPress adivaha Travel Plugin version 2.3 contains a time‑based blind SQL injection that can be triggered by an unauthenticated attacker using the 'pid' GET parameter on the /mobile-app/v3/ endpoint. The vulnerability allows the attacker to inject XOR‑based SQL payloads that cause the database to pause, revealing data character by character or exhausting resources, resulting in data exposure or denial of service.
Affected Systems
Adivaha's WordPress adivaha Travel Plugin, specifically version 2.3, is affected by this flaw. Administrators using this plugin on any WordPress site should verify their installed version. No additional vendor product versions are listed in the advisory; therefore, only the stated version should be considered vulnerable.
Risk and Exploitability
The CVSS score of 8.8 signals a high severity, with attackers able to exploit the flaw remotely without authentication. The EPSS score is unavailable, so the current exploit probability is undetermined, but the known existence of an exploitation script on ExploitDB indicates that the vulnerability is actively tracked. Because the endpoint is publicly reachable, the attack vector is purely over HTTP, and an attacker simply needs to craft a URL containing the malicious 'pid' value to trigger the injection. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment