CVE-2025-52714: WordPress Traveler theme < 3.2.2 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler allows SQL Injection. This issue affects Traveler: from n/a through n/a.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows SQL Injection.This issue affects Traveler: from n/a through < 3.2.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52714?
CVE-2025-52714 is considered a critical vulnerability due to its potential for SQL Injection attacks.
How do I fix CVE-2025-52714?
To fix CVE-2025-52714, update the Traveler theme to the latest version recommended by the vendor.
What software is affected by CVE-2025-52714?
CVE-2025-52714 affects the WordPress Traveler theme versions up to 3.2.2.
What is the main issue with CVE-2025-52714?
The main issue with CVE-2025-52714 is improper neutralization of special elements used in SQL commands, leading to SQL Injection.
Can CVE-2025-52714 be exploited remotely?
Yes, CVE-2025-52714 can be exploited remotely, allowing attackers to manipulate the database via SQL Injection.