Thème WordPress
Vulnérabilités Travel Booking WordPress Theme
Cette page rassemble les failles publiées pour Travel Booking WordPress Theme, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Travel Booking WordPress Theme
24 fiches
Travel Booking WordPress Theme < 3.2.8.1 – Unauthenticated PHP Object Injection
The Travel Booking WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to 3.2.8.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known…
[*, 3.2.8.1)
3.2.8.1
17/03/2026
Traveler < 3.2.8 – Authenticated (Contributor+) SQL Injection
The Traveler theme for WordPress is vulnerable to SQL Injection in versions up to 3.2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
[*, 3.2.8)
3.2.8
22/01/2026
Traveler <= 3.2.6 – Missing Authorization
The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.6. This makes it possible for unauthenticated attackers to…
*-3.2.6
3.2.7
05/01/2026
Traveler < 3.2.6 – Reflected Cross-Site Scripting
The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
[*, 3.2.6)
3.2.6
07/11/2025
Traveler < 3.2.6 – Authenticated (Subscriber+) SQL Injection
The Traveler theme for WordPress is vulnerable to SQL Injection in versions up to 3.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
[*, 3.2.6)
3.2.6
07/11/2025
Traveler <= 3.2.6 – Missing Authorization
The Traveler theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.2.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
*-3.2.6
Non indiqué
07/11/2025
Traveler < 3.2.6 – Unauthenticated Local File Inclusion
The Traveler theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.2.6. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP…
[*, 3.2.6)
3.2.6
06/11/2025
Travel Booking WordPress Theme < 3.2.3 – Reflected Cross-Site Scripting
The Travel Booking WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 3.2.3 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
[*, 3.2.3)
3.2.3
06/09/2025
Travel Booking WordPress Theme < 3.2.3 – Missing Authorization to Unauthenticated Arbitrary Content Deletion
The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 3.2.3 (exclusive). This makes it possible for unauthenticated attackers to delete…
[*, 3.2.3)
3.2.3
06/09/2025
Traveler < 3.2.2 – Unauthenticated SQL Injection
The Traveler theme for WordPress is vulnerable to SQL Injection in versions up to 3.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
[*, 3.2.2)
3.2.2
10/07/2025
Traveler < 3.2.1 – Unauthenticated PHP Object Injection
The Traveler theme for WordPress is vulnerable to PHP Object Injection in versions up to 3.2.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is…
[*, 3.2.1)
3.2.1
27/03/2025
Traveler <= 3.2.0 – Unauthenticated SQL Injection
The Traveler theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-3.2.0
3.2.1
27/03/2025
Traveler <= 3.2.0 – Missing Authorization
The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with…
*-3.2.0
3.2.1
27/03/2025
Traveler <= 3.2.0 – Missing Authorization
The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.0. This makes it possible for unauthenticated attackers to…
*-3.2.0
3.2.1
27/03/2025
Traveler <= 3.1.8 – Unauthenticated Local File Inclusion via hotel_alone_load_more_post
The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_load_more_post' function 'style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files…
*-3.1.8
3.1.9
14/03/2025
Traveler <= 3.1.8 – Reflected Cross-Site Scripting
The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-3.1.8
3.1.9
14/03/2025
Traveler <= 3.1.9 – Authenticated (Contributor+) Local File Inclusion via Shortcode
The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.9 via shortcodes. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary…
*-3.1.9
3.2.0
27/02/2025
Traveler <= 3.1.6 – Unauthenticated SQL Injection via order_id
The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id’ parameter in all versions up to, and including, 3.1.6 due to insufficient escaping on the user supplied parameter and lack…
*-3.1.6
3.1.7
17/12/2024
Traveler <= 3.1.6 – Missing Authorization in Several AJAX Actions
The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '__stPartnerCreateServiceRental', 'st_delete_order_item', '_st_partner_approve_booking', 'save_order_item', and '__userDenyEachInfo' functions in all versions up to, and including, 3.1.6.…
*-3.1.6
3.1.7
17/12/2024
Traveler – Travel Booking WordPress Theme < 2.8.4 – Cross-Site Scripting
The Traveler – Travel Booking WordPress Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘child_number’ parameter in versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible…
[*, 2.8.4)
2.8.4
23/06/2020
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.