Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through 3.2.9.
Published: 2026-10-09
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Blind SQL Injection
Action: Apply Patch
AI Analysis

Impact

This vulnerability permits an attacker to inject malicious SQL into database queries by exploiting insufficient escaping of special elements in the WordPress Traveler theme. The flaw could allow a remote attacker to retrieve, modify, or delete data from the backing database, compromising data confidentiality, integrity, and availability. The weakness is identified as CWE‑89, indicating that input is used in SQL commands without proper sanitization.

Affected Systems

The issue affects the Shinetheme Traveler theme for WordPress in all versions from the earliest release up to and including 3.2.9. Any WordPress site that has not upgraded past version 3.2.9 is potentially vulnerable and requires assessment.

Risk and Exploitability

The CVSS score of 9.3 classifies this as a critical vulnerability, while no EPSS score is available, indicating limited public exploitation data. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is remote, accessed via a web interface that processes user input. An attacker could craft special characters in query parameters or form fields to trigger blind SQL injection, assuming the database user has sufficient privileges. No additional exploitation conditions are described, so the risk remains high in any environment where the vulnerable theme is active.

Generated by OpenCVE AI on October 9, 2026 at 11:27 UTC.

Remediation

Vendor Solution

Update the WordPress Traveler theme to the latest available version (at least 3.3).


OpenCVE Recommended Actions

  • Update the WordPress Traveler theme to version 3.3 or later.
  • If an immediate update is not possible, limit the database user’s privileges so that the WordPress database cannot modify or delete critical tables.
  • Configure the web application firewall to filter or block suspicious SQL patterns that could trigger injection attempts.

Generated by OpenCVE AI on October 9, 2026 at 11:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through 3.2.9.
Title WordPress Traveler theme <= 3.2.9 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:36.351Z

Reserved: 2026-09-19T00:23:25.966Z

Link: CVE-2026-93947

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T10:16:39.520

Modified: 2026-10-09T10:16:39.520

Link: CVE-2026-93947

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T11:30:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')