theme

Traveler Vulnerabilities

59 known security issues reported for the Traveler WordPress theme. Most recent disclosed Mar 17, 2026.

4 critical 7 high 14 medium

Running Traveler on your site? Check whether your installed version is affected.

Scan your site free

Traveler - PHP Object Injection vulnerability

critical

PHP Object Injection vulnerability

CVSS:
9.8
Affected:
up to 3.2.8.1
Fixed in:
3.2.8.1
Disclosed:
Mar 17, 2026

Travel Booking WordPress Theme < 3.2.8.1 - Unauthenticated PHP Object Injection

high

The Travel Booking WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to 3.2.8.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present...

CVSS:
8.1
Affected:
up to 3.2.8.1
Fixed in:
3.2.8.1
Disclosed:
Mar 17, 2026

CVE-2026-25449 on NVD →

Traveler < 3.2.8 - Authenticated (Contributor+) SQL Injection

medium

The Traveler theme for WordPress is vulnerable to SQL Injection in versions up to 3.2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additio...

CVSS:
6.5
Affected:
up to 3.2.8
Fixed in:
3.2.8
Disclosed:
Jan 22, 2026

CVE-2026-24367 on NVD →

Travel Booking [traveler] < 3.2.8

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through < 3.2.8.

Affected:
up to 3.2.8
Fixed in:
3.2.8
Disclosed:
Jan 22, 2026

CVE-2026-24367 on NVD →

Travel Booking [traveler] <= 3.2.6 (unfixed)

unknown

[en] Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through <= 3.2.6.

Affected:
up to 3.2.6
Fix:
No patched version reported
Disclosed:
Jan 8, 2026

CVE-2025-67917 on NVD →

Traveler <= 3.2.6 - Missing Authorization

medium

The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.2.6
Fixed in:
3.2.7
Disclosed:
Jan 5, 2026

CVE-2025-67917 on NVD →

Travel Booking [traveler] < 3.2.6

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through < 3.2.6.

Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Dec 18, 2025

CVE-2025-64371 on NVD →

Travel Booking [traveler] < 3.2.6

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Traveler traveler allows Reflected XSS.This issue affects Traveler: from n/a through < 3.2.6.

Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Dec 18, 2025

CVE-2025-64372 on NVD →

Travel Booking [traveler] < 3.2.6

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in shinetheme Traveler traveler allows PHP Local File Inclusion.This issue affects Traveler: from n/a through < 3.2.6.

Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Dec 18, 2025

CVE-2025-64373 on NVD →

Travel Booking [traveler] <= 3.2.6 (unfixed)

unknown

[en] Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through <= 3.2.6.

Affected:
up to 3.2.6
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-63028 on NVD →

Traveler < 3.2.6 - Authenticated (Subscriber+) SQL Injection

medium

The Traveler theme for WordPress is vulnerable to SQL Injection in versions up to 3.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append addition...

CVSS:
6.5
Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Nov 7, 2025

CVE-2025-64371 on NVD →

Traveler < 3.2.6 - Reflected Cross-Site Scripting

medium

The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into perfo...

CVSS:
6.1
Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Nov 7, 2025

CVE-2025-64372 on NVD →

Traveler <= 3.2.6 - Missing Authorization

medium

The Traveler theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.2.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.2.6
Fix:
No patched version reported
Disclosed:
Nov 7, 2025

CVE-2025-63028 on NVD →

Traveler < 3.2.6 - Unauthenticated Local File Inclusion

high

The Traveler theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.2.6. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive d...

CVSS:
8.1
Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Nov 6, 2025

CVE-2025-64373 on NVD →

Travel Booking [traveler] < 3.2.3

unknown

[en] Missing Authorization vulnerability in shinetheme Traveler allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Traveler: from n/a through n/a.

Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Sep 26, 2025

CVE-2025-59011 on NVD →

Travel Booking [traveler] < 3.2.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Traveler allows Reflected XSS. This issue affects Traveler: from n/a through n/a.

Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Sep 26, 2025

CVE-2025-59012 on NVD →

Travel Booking WordPress Theme < 3.2.3 - Reflected Cross-Site Scripting

medium

The Travel Booking WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 3.2.3 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they ca...

CVSS:
6.1
Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Sep 6, 2025

CVE-2025-59012 on NVD →

Travel Booking WordPress Theme < 3.2.3 - Missing Authorization to Unauthenticated Arbitrary Content Deletion

medium

The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 3.2.3 (exclusive). This makes it possible for unauthenticated attackers to delete arbitrary content.

CVSS:
5.3
Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Sep 6, 2025

CVE-2025-59011 on NVD →

Travel Booking [traveler] < 3.2.2

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler allows SQL Injection. This issue affects Traveler: from n/a through n/a.

Affected:
up to 3.2.2
Fixed in:
3.2.2
Disclosed:
Jul 16, 2025

CVE-2025-52714 on NVD →

Traveler < 3.2.2 - Unauthenticated SQL Injection

high

The Traveler theme for WordPress is vulnerable to SQL Injection in versions up to 3.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing q...

CVSS:
7.5
Affected:
up to 3.2.2
Fixed in:
3.2.2
Disclosed:
Jul 10, 2025

CVE-2025-52714 on NVD →

Traveler < 3.2.1 - Unauthenticated PHP Object Injection

critical

The Traveler theme for WordPress is vulnerable to PHP Object Injection in versions up to 3.2.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin...

CVSS:
9.8
Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Mar 27, 2025

CVE-2025-26873 on NVD →

Traveler <= 3.2.0 - Unauthenticated SQL Injection

high

The Traveler theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into al...

CVSS:
7.5
Affected:
up to 3.2.0
Fixed in:
3.2.1
Disclosed:
Mar 27, 2025

CVE-2025-26898 on NVD →

Traveler <= 3.2.0 - Missing Authorization

medium

The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.2.0
Fixed in:
3.2.1
Disclosed:
Mar 27, 2025

CVE-2025-26733 on NVD →

Traveler <= 3.2.0 - Missing Authorization

medium

The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.2.0
Fixed in:
3.2.1
Disclosed:
Mar 27, 2025

CVE-2025-26956 on NVD →

Travel Booking [traveler] < 3.2.1

unknown

[en] Missing Authorization vulnerability in Shinetheme Traveler.This issue affects Traveler: from n/a through 3.1.8.

Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Mar 27, 2025

CVE-2025-26733 on NVD →

Travel Booking [traveler] < 3.2.1

unknown

[en] Missing Authorization vulnerability in Shinetheme Traveler.This issue affects Traveler: from n/a through 3.1.8.

Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Mar 27, 2025

CVE-2025-26956 on NVD →

Travel Booking [traveler] < 3.2.1

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler.This issue affects Traveler: from n/a through 3.1.8.

Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Mar 27, 2025

CVE-2025-26898 on NVD →

Travel Booking [traveler] <= 3.1.8 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in Shine theme Traveler.This issue affects Traveler: from n/a before 3.2.1.

Affected:
up to 3.1.8
Fix:
No patched version reported
Disclosed:
Mar 27, 2025

CVE-2025-26873 on NVD →

Traveler <= 3.1.8 - Unauthenticated Local File Inclusion via hotel_alone_load_more_post

critical

The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_load_more_post' function 'style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP...

CVSS:
9.8
Affected:
up to 3.1.8
Fixed in:
3.1.9
Disclosed:
Mar 14, 2025

CVE-2025-1771 on NVD →

Traveler <= 3.1.8 - Reflected Cross-Site Scripting

medium

The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if t...

CVSS:
6.1
Affected:
up to 3.1.8
Fixed in:
3.1.9
Disclosed:
Mar 14, 2025

CVE-2025-1773 on NVD →

Traveler <= 3.1.9 - Authenticated (Contributor+) Local File Inclusion via Shortcode

high

The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.9 via shortcodes. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP cod...

CVSS:
8.8
Affected:
up to 3.1.9
Fixed in:
3.2.0
Disclosed:
Feb 27, 2025

CVE-2024-12811 on NVD →

Travel Booking [traveler] < 3.2.0

unknown

[en] The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_slider' shortcode 'style' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on th...

Affected:
up to 3.2.0
Fixed in:
3.2.0
Disclosed:
Feb 27, 2025

CVE-2024-12811 on NVD →

Travel Booking [traveler] < 3.1.7

unknown

[en] The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '__stPartnerCreateServiceRental', 'st_delete_order_item', '_st_partner_approve_booking', 'save_order_item', and '__userDenyEachInfo' functions in all versions up to, a...

Affected:
up to 3.1.7
Fixed in:
3.1.7
Disclosed:
Dec 18, 2024

CVE-2024-11926 on NVD →

Travel Booking [traveler] < 3.1.7

unknown

[en] The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id’ parameter in all versions up to, and including, 3.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it po...

Affected:
up to 3.1.7
Fixed in:
3.1.7
Disclosed:
Dec 18, 2024

CVE-2024-11912 on NVD →

Traveler <= 3.1.6 - Unauthenticated SQL Injection via order_id

high

The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id’ parameter in all versions up to, and including, 3.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibl...

CVSS:
7.5
Affected:
up to 3.1.6
Fixed in:
3.1.7
Disclosed:
Dec 17, 2024

CVE-2024-11912 on NVD →

Traveler <= 3.1.6 - Missing Authorization in Several AJAX Actions

medium

The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '__stPartnerCreateServiceRental', 'st_delete_order_item', '_st_partner_approve_booking', 'save_order_item', and '__userDenyEachInfo' functions in all versions up to, and in...

CVSS:
6.5
Affected:
up to 3.1.6
Fixed in:
3.1.7
Disclosed:
Dec 17, 2024

CVE-2024-11926 on NVD →

Travel Booking [traveler] < 2.8.4

unknown

Unauthenticated SQL Injection (SQLi) vulnerability found by Vlad Vector in WordPress Travel Booking theme (versions <= 2.8.3).

Affected:
up to 2.8.4
Fixed in:
2.8.4
Disclosed:
Jul 9, 2020

Travel Booking [traveler] < 2.8.4

unknown

Unauthenticated Cross-Site Scripting (XSS) vulnerability found by Vlad Vector in WordPress Travel Booking theme (versions <= 2.8.3).

Affected:
up to 2.8.4
Fixed in:
2.8.4
Disclosed:
Jul 9, 2020

Travel Booking WordPress Theme < 2.8.4 - SQL Injection

critical

The Travel Booking WordPress Theme for WordPress is vulnerable to blind SQL Injection via the ‘location_id’ parameter in versions up to, and including, 2.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for ;unauthentic...

CVSS:
9.8
Affected:
up to 2.8.4
Fixed in:
2.8.4
Disclosed:
Jun 23, 2020

Traveler – Travel Booking WordPress Theme < 2.8.4 - Cross-Site Scripting

medium

The Traveler – Travel Booking WordPress Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘child_number’ parameter in versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...

CVSS:
6.1
Affected:
up to 2.8.4
Fixed in:
2.8.4
Disclosed:
Jun 23, 2020

Travel Booking [traveler] < 2.8.4

unknown

The Travel Booking WordPress Theme for WordPress is vulnerable to blind SQL Injection via the ‘location_id’ parameter in versions up to, and including, 2.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for ;unauthentic...

Affected:
up to 2.8.4
Fixed in:
2.8.4
Disclosed:
Jun 23, 2020

Travel Booking [traveler] < 2.8.4

unknown

The Traveler – Travel Booking WordPress Theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘child_number’ parameter in versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...

Affected:
up to 2.8.4
Fixed in:
2.8.4
Disclosed:
Jun 23, 2020

Travel Booking [traveler] < 2.8.2

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found by Vlad Vector in WordPress Travel Booking theme (versions <= 2.8.1).

Affected:
up to 2.8.2
Fixed in:
2.8.2
Disclosed:
Jun 19, 2020

Travel Booking WordPress Theme < 2.8.2 - Cross-Site Scripting

medium

The "Travel Booking WordPress Theme" theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘adult_number’ parameter in versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

CVSS:
6.1
Affected:
up to 2.8.1
Fixed in:
2.8.2
Disclosed:
Jun 17, 2020

Travel Booking [traveler] < 2.8.2

unknown

The "Travel Booking WordPress Theme" theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘adult_number’ parameter in versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

Affected:
up to 2.8.2
Fixed in:
2.8.2
Disclosed:
Jun 17, 2020

Traveler – Travel Booking WordPress Theme < 2.7.8.6 - Cross-Site Scripting

high

The Traveler – Travel Booking WordPress Theme for WordPress is vulnerable to both Reflected and Stored Cross-Site Scripting in versions up to, and including, 2.7.8.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim'...

CVSS:
8.3
Affected:
up to 2.7.8.6
Fixed in:
2.7.8.6
Disclosed:
Jan 13, 2020

Travel Booking [traveler] < 2.7.8.6

unknown

The Traveler – Travel Booking WordPress Theme for WordPress is vulnerable to both Reflected and Stored Cross-Site Scripting in versions up to, and including, 2.7.8.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim'...

Affected:
up to 2.7.8.6
Fixed in:
2.7.8.6
Disclosed:
Jan 13, 2020

Travel Booking [traveler] < 2.7.8.6

unknown

Reflected & Persistent Cross-Site Scripting (XSS) vulnerabilities found by m0ze in WordPress Travel Booking theme (versions <= 2.7.8.5).

Affected:
up to 2.7.8.6
Fixed in:
2.7.8.6
Disclosed:
Jan 13, 2020

Travel Booking [traveler] < 2.7.1

unknown

Reflected & Stored Cross-Site Scripting XSS vulnerability found by QUIXSS in WordPress Traveler - Travel Booking Theme (versions <= 2.7.1).

Affected:
up to 2.7.1
Fixed in:
2.7.1
Disclosed:
Jun 11, 2019

Travel Booking WordPress Theme < 2.7.8.4 - Cross-Site Scripting

medium

The Travel Booking WordPress Theme for WordPress is vulnerable to both Reflected and Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.7.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

CVSS:
6.4
Affected:
up to 2.7.8.4
Fixed in:
2.7.8.4
Disclosed:
May 5, 2019

Travel Booking [traveler] < 2.7.8.4

unknown

Reflected & Stored Cross-Site Scripting (XSS) vulnerabilities found by QUIXSS in WordPress Travel Booking theme (versions <= 2.7.8.3).

Affected:
up to 2.7.8.4
Fixed in:
2.7.8.4
Disclosed:
May 5, 2019

Travel Booking [traveler] < 2.7.8.4

unknown

The Travel Booking WordPress Theme for WordPress is vulnerable to both Reflected and Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.7.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

Affected:
up to 2.7.8.4
Fixed in:
2.7.8.4
Disclosed:
May 5, 2019

Travel Booking [traveler] < 2.8.2

unknown

Unauthenticated Reflected XSS vulnerability was discovered in the &laquo;Travel Booking WordPress Theme&raquo;, tested version &mdash; v2.8.1. Edit (WPScanTeam) June 17th, 2020 - Confirmed &amp; Escalated to Envato. June 18th, 2020 - v2.8.2 released, fixing the issue.

Affected:
up to 2.8.2
Fixed in:
2.8.2

Travel Booking [traveler] < 2.8.4

unknown

Unauthenticated SQL Injection via the location_id parameter

Affected:
up to 2.8.4
Fixed in:
2.8.4

Travel Booking [traveler] < 2.7.8.4

unknown

Weak security measures like no input &amp; textarea fields data filtering has been discovered in the &#039;Traveler - Travel Booking WordPress Theme&#039;. Special Notes: 1 - &#039;Change Avatar&#039; upload field works really strange. F.e., u can upload any .PHP file with extension .php.png and break profile page...

Affected:
up to 2.7.8.4
Fixed in:
2.7.8.4

Travel Booking [traveler] < 2.8.4

unknown

Unauthenticated Reflected XSS via the child_number parameter

Affected:
up to 2.8.4
Fixed in:
2.8.4

Travel Booking [traveler] < 2.7.8.6

unknown

Reflected &amp; Persistent XSS vulnerability was discovered in the &#039;Travel Booking WordPress Theme&#039;, tested version &mdash; v2.7.8.5 Edit (WPScanTeam): January 11th, 2020 - Report received &amp; Envato contacted January 12th, 2020 - Report updated with Reflected XSS, Envato notified again. January 12th,...

Affected:
up to 2.7.8.6
Fixed in:
2.7.8.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database