Sceawere
Vulnerability Detail
CVE-2026-93947UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Traveler SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.3
- Creation Date
- 3h ago
- Vendor
- Shinetheme
- Product
- Traveler
- Attack Type
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through 3.2.9.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.3",
"pubDate": "2026-10-09T10:16:39.520Z",
"pubdate": "2026-10-09T10:16:39.520Z",
"executiveSummary": "The Traveler plugin for WordPress is affected by an Improper Neutralization of Special Elements used in an SQL Command vulnerability, classified as Blind SQL Injection.\nThis security flaw allows an unauthenticated or authenticated attacker to inject arbitrary SQL queries into the database through the application's input vectors.\nThe vulnerability resides in versions of Traveler from n/a through 3.2.9.\nSuccessful exploitation enables unauthorized database interaction, potentially leading to the extraction of sensitive data, such as user credentials, configuration details, or other proprietary information stored within the WordPress database.\nThe risk implication is critical, as Blind SQL Injection provides a stealthy method for attackers to exfiltrate data bit-by-bit by observing the application's responses to true/false boolean queries.\nNo specific authentication or advanced privileges are explicitly required for the initial entry point, increasing the overall attack surface and potential for automated exploitation.",
"technicalDetails": "The vulnerability is rooted in the failure of the Traveler plugin to properly sanitize and parameterize user-supplied input before incorporating it into database queries. Specifically, the application fails to utilize prepared statements or appropriate escaping mechanisms when processing input parameters, thereby permitting the injection of arbitrary SQL syntax.\nThe identified flaw is a Blind SQL Injection, which occurs when the application is vulnerable to SQL injection, but its HTTP responses do not contain the results of the relevant SQL query or any database errors. Instead, the attacker must infer the data by sending specialized payloads that trigger different application behaviors based on the truth value of a condition (Boolean-based) or by inducing time delays (Time-based).\nThe attack flow typically initiates when an attacker identifies an input parameter—such as those found in GET or POST requests used for searching, filtering, or sorting data within the Traveler plugin—that is passed directly into a database query. By injecting boolean logic (e.g., 'AND 1=1' vs 'AND 1=0') or time-delay functions (e.g., SLEEP()), the attacker monitors the server's response time or content variance to confirm vulnerability.\nOnce the vulnerability is confirmed, the attacker can systematically map the database schema. By injecting iterative queries, the attacker can extract information character-by-character from system tables, including administrator account hashes, user metadata, and other sensitive plugin configurations. Because the application processes these inputs server-side, the database executes the malicious commands with the privileges assigned to the web application's database user, which often possesses excessive permissions.\nThe affected component is the Traveler plugin, specifically the code responsible for handling database queries related to its core functionality. All versions ranging from n/a up to and including 3.2.9 are susceptible to this vector. Given the nature of WordPress plugins, this vulnerability is exposed over the network, allowing remote attackers to target the application without prior knowledge of the internal administrative environment, provided they can reach the vulnerable entry point."
}