Impact
This vulnerability permits an attacker to inject malicious SQL into database queries by exploiting insufficient escaping of special elements in the WordPress Traveler theme. The flaw could allow a remote attacker to retrieve, modify, or delete data from the backing database, compromising data confidentiality, integrity, and availability. The weakness is identified as CWE‑89, indicating that input is used in SQL commands without proper sanitization.
Affected Systems
The issue affects the Shinetheme Traveler theme for WordPress in all versions from the earliest release up to and including 3.2.9. Any WordPress site that has not upgraded past version 3.2.9 is potentially vulnerable and requires assessment.
Risk and Exploitability
The CVSS score of 9.3 classifies this as a critical vulnerability, while no EPSS score is available, indicating limited public exploitation data. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is remote, accessed via a web interface that processes user input. An attacker could craft special characters in query parameters or form fields to trigger blind SQL injection, assuming the database user has sufficient privileges. No additional exploitation conditions are described, so the risk remains high in any environment where the vulnerable theme is active.
OpenCVE Enrichment