Impact
The vulnerability is an SQL injection flaw caused by improper neutralization of special elements in an SQL command within the shinetheme Traveler WordPress theme. This flaw allows an attacker to inject arbitrary SQL statements, which can lead to unauthorized data disclosure, modification, or even execution of arbitrary code on the server if the database user privileges are high enough.
Affected Systems
The affected product is the shinetheme Traveler WordPress theme, any installation running a version earlier than 3.2.2. Versions from the earliest release up to but not including 3.2.2 are susceptible.
Risk and Exploitability
The CVSS base score of 9.3 indicates a critical severity, while the EPSS score of less than 1% shows a low likelihood of exploitation at this time; however the vulnerability is not listed in CISA KEV. The flaw can be exploited remotely through crafted HTTP requests that target vulnerable input fields, likely without authentication, allowing an attacker to execute arbitrary SQL commands against the site’s database.
OpenCVE Enrichment
EUVD