Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-93947: Traveler WordPress theme lets attackers query your database
CVE-2026-93947 · published 2 days ago
Summary
The Traveler theme for WordPress up to version 3.2.9 contains a flaw that allows an attacker to send specially crafted input and cause hidden database queries. This could let them view or change data stored by your site. Upgrade the theme to a newer version or replace it until a fix is applied.
What to do
- Update shinetheme traveler to version 3.3.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| shinetheme | traveler |
<= 3.2.9 Fix: upgrade to 3.3
|
Original advisory text
WordPress Traveler theme <= 3.2.9 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through 3.2.9.
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Type
CWE-89SQL Injection
Timeline
Published9 Oct 2026
Updated11 Oct 2026
First seen9 Oct 2026
Track software like this
Free during beta