Executive brief
WP Travel Gutenberg Blocks is a WordPress plugin used to display travel and trekking information on websites. A critical security flaw allows unauthenticated attackers to interact directly with the site's database. This could lead to the theft of sensitive customer information, site data, or disruption of operations.
Technical details
A Blind SQL Injection vulnerability exists in the WP Travel Gutenberg Blocks plugin for WordPress due to improper neutralization of special elements used in SQL commands. The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the application to execute arbitrary SQL queries against the backend database. Successful exploitation could allow an attacker to extract sensitive information from the database or cause partial service disruption. The vulnerability affects all versions up to and including 3.9.4 and has been addressed in version 3.9.5.
Affected products
- WP Travel WP Travel Gutenberg Blocks n/a through 3.9.4
Timeline
- 2026-02-28: other: Reported by researcher daroo
- 2026-06-17: advisory: Published by Patchstack and NVD
- 2026-06-17: patched: Version 3.9.5 released to address the issue