Executive brief
WP Travel is a WordPress plugin used to manage travel bookings and itineraries. A security flaw in this plugin allows an attacker with basic user permissions to perform a blind SQL injection attack. This could lead to the unauthorized extraction of sensitive information from the website's database, potentially compromising customer data or site configuration.
Technical details
A blind SQL injection vulnerability exists in the WP Travel plugin for WordPress due to improper neutralization of special elements used in SQL commands. The flaw is present in versions up to and including 11.4.0. An attacker with 'Contributor' level privileges or higher can exploit this via network requests to interact directly with the database. While the impact is primarily focused on data confidentiality (C:H), the vulnerability allows for the extraction of sensitive data through inference. The issue is addressed in version 11.5.0.
Affected products
- WP Travel WP Travel <= 11.4.0
Timeline
- 2026-04-09: other: Reported by Nhut Quang
- 2026-05-09: disclosed: Initial disclosure by Patchstack
- 2026-05-12: advisory: CVE published to NVD
- 2026-05-09: patched: Version 11.5.0 released to address the vulnerability