Thème WordPress

Vulnérabilités Travel Booking WordPress Theme

Cette page rassemble les failles publiées pour Travel Booking WordPress Theme, leurs plages de versions affectées et les correctifs signalés dans la base locale.

24Vulnérabilités
3Critiques
23Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Travel Booking WordPress Theme

24 fiches

CVE-2025-59012 Moyenne · 6,1
Travel Booking WordPress Theme

Travel Booking WordPress Theme < 3.2.3 – Reflected Cross-Site Scripting

The Travel Booking WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 3.2.3 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

Versions affectées

[*, 3.2.3)

Correctif

3.2.3

Publication

06/09/2025

CVE-2025-59011 Moyenne · 5,3
Travel Booking WordPress Theme

Travel Booking WordPress Theme < 3.2.3 – Missing Authorization to Unauthenticated Arbitrary Content Deletion

The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 3.2.3 (exclusive). This makes it possible for unauthenticated attackers to delete…

Versions affectées

[*, 3.2.3)

Correctif

3.2.3

Publication

06/09/2025

CVE-2025-1771 Critique · 9,8
Travel Booking WordPress Theme

Traveler <= 3.1.8 – Unauthenticated Local File Inclusion via hotel_alone_load_more_post

The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_load_more_post' function 'style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files…

Versions affectées

*-3.1.8

Correctif

3.1.9

Publication

14/03/2025

CVE-2024-12811 Élevée · 8,8
Travel Booking WordPress Theme

Traveler <= 3.1.9 – Authenticated (Contributor+) Local File Inclusion via Shortcode

The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.9 via shortcodes. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary…

Versions affectées

*-3.1.9

Correctif

3.2.0

Publication

27/02/2025

CVE-2024-11926 Moyenne · 6,5
Travel Booking WordPress Theme

Traveler <= 3.1.6 – Missing Authorization in Several AJAX Actions

The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '__stPartnerCreateServiceRental', 'st_delete_order_item', '_st_partner_approve_booking', 'save_order_item', and '__userDenyEachInfo' functions in all versions up to, and including, 3.1.6.…

Versions affectées

*-3.1.6

Correctif

3.1.7

Publication

17/12/2024

Vulnérabilité Moyenne · 6,1
Travel Booking WordPress Theme

Traveler – Travel Booking WordPress Theme < 2.8.4 – Cross-Site Scripting

The Traveler – Travel Booking WordPress Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘child_number’ parameter in versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

[*, 2.8.4)

Correctif

2.8.4

Publication

23/06/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités