What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.
Explanation of Vulnerability in Simple Terms
WP Travel Engine versions up to 5.7.9 contain a SQL injection vulnerability in a high-privilege function. An authenticated admin or high-level user can craft malicious input to read sensitive database information. The vulnerability requires admin-level access and does not allow data modification, but can expose customer data, payment records, or other stored information.
What an attacker can do
Read sensitive data from the site's database, including customer information and booking records.
Potential impact on your site
A compromised admin account could expose customer data, bookings, and payment information stored in your database.
Conditions required to exploit
Attacker must have admin or high-level user account access to the WordPress site.
Key dates
External resources
Related vulnerabilities