Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-93947: Traveler WordPress theme lets attackers query your database

CVE-2026-93947 · published 2 days ago
Summary

The Traveler theme for WordPress up to version 3.2.9 contains a flaw that allows an attacker to send specially crafted input and cause hidden database queries. This could let them view or change data stored by your site. Upgrade the theme to a newer version or replace it until a fix is applied.

What to do
  • Update shinetheme traveler to version 3.3.
Affected software
VendorProductAffected versions
shinetheme traveler <= 3.2.9
Fix: upgrade to 3.3
Original advisory text
WordPress Traveler theme <= 3.2.9 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through 3.2.9.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-89SQL Injection
Timeline
Published9 Oct 2026
Updated11 Oct 2026
First seen9 Oct 2026
Sources
CVE-2026-93947 · MITRE
Track software like this
Free during beta