What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.
Explanation of Vulnerability in Simple Terms
WP Travel Engine versions up to 5.7.9 contain a SQL injection vulnerability in an unauthenticated endpoint. An attacker can craft malicious input to extract sensitive data from the site's database, including user credentials and travel booking information. The vulnerability requires no authentication or user interaction to exploit.
What an attacker can do
Extract sensitive data from the site database, including user credentials and booking records.
Potential impact on your site
Attackers can read all database contents without logging in, exposing customer data and site configuration.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities