Travel Booking WordPress Theme

Explore Travel Booking WordPress Theme vulnerabilities across all versions. Currently tracking 24 known vulnerabilities, including severity, impact, and patch status.

01234567891005.05.2019Today05.05.20196.4Travel Booking WordPress Theme < 2.7.8.4 - Cross-Site Scripting CVSS 6.4 · 05.05.201913.01.20208.3Traveler – Travel Booking WordPress Theme < 2.7.8.6 - Cross-Site Scripting CVSS 8.3 · 13.01.202017.06.20206.1Travel Booking WordPress Theme < 2.8.2 - Cross-Site Scripting CVSS 6.1 · 17.06.202023.06.20209.8Travel Booking WordPress Theme < 2.8.4 - SQL Injection CVSS 9.8 · 23.06.20206.1Traveler – Travel Booking WordPress Theme < 2.8.4 - Cross-Site Scripting CVSS 6.1 · 23.06.202017.12.20246.5Traveler <= 3.1.6 - Missing Authorization in Several AJAX Actions CVSS 6.5 · 17.12.20247.5Traveler <= 3.1.6 - Unauthenticated SQL Injection via order_id CVSS 7.5 · 17.12.202427.02.20258.8Traveler <= 3.1.9 - Authenticated (Contributor+) Local File Inclusion via Shortcode CVSS 8.8 · 27.02.202514.03.20256.1Traveler <= 3.1.8 - Reflected Cross-Site Scripting CVSS 6.1 · 14.03.20259.8Traveler <= 3.1.8 - Unauthenticated Local File Inclusion via hotel_alone_load_more_post CVSS 9.8 · 14.03.202527.03.20257.5Traveler <= 3.2.0 - Unauthenticated SQL Injection CVSS 7.5 · 27.03.20259.8Traveler < 3.2.1 - Unauthenticated PHP Object Injection CVSS 9.8 · 27.03.20254.3Traveler <= 3.2.0 - Missing Authorization CVSS 4.3 · 27.03.20255.3Traveler <= 3.2.0 - Missing Authorization CVSS 5.3 · 27.03.202510.07.20257.5Traveler < 3.2.2 - Unauthenticated SQL Injection CVSS 7.5 · 10.07.202506.09.20256.1Travel Booking WordPress Theme < 3.2.3 - Reflected Cross-Site Scripting CVSS 6.1 · 06.09.20255.3Travel Booking WordPress Theme < 3.2.3 - Missing Authorization to Unauthenticated Arbitrary Content Deletion CVSS 5.3 · 06.09.202506.11.20258.1Traveler < 3.2.6 - Unauthenticated Local File Inclusion CVSS 8.1 · 06.11.202507.11.20256.5Traveler < 3.2.6 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 07.11.20255.3Traveler <= 3.2.6 - Missing Authorization CVSS 5.3 · 07.11.20256.1Traveler < 3.2.6 - Reflected Cross-Site Scripting CVSS 6.1 · 07.11.202505.01.20265.3Traveler <= 3.2.6 - Missing Authorization CVSS 5.3 · 05.01.202622.01.20266.5Traveler < 3.2.8 - Authenticated (Contributor+) SQL Injection CVSS 6.5 · 22.01.202617.03.20268.1Travel Booking WordPress Theme < 3.2.8.1 - Unauthenticated PHP Object Injection CVSS 8.1 · 17.03.2026

Strategic Overview

Avg CVSSMedium
7.0/ 10
Patch Coverage96%
Open

1

Fixed

23

Get automatic notifications for all Travel Booking WordPress Theme vulnerabilities before they are exploited.

Vulnerability Records

24 records
2026-03-17 00:00CVE-2026-25449
8.1
High
Phat RiOYes
2026-01-22 00:00CVE-2026-24367
6.5
Medium
João Pedro Soares de AlcântaraYes
2026-01-05 00:00CVE-2025-67917
5.3
Medium
Rafie MuhammadYes
2025-11-07 00:00CVE-2025-64371
6.5
Medium
João Pedro Soares de AlcântaraYes
2025-11-07 00:00CVE-2025-63028
5.3
Medium
João Pedro Soares de AlcântaraNo
2025-11-07 00:00CVE-2025-64372
6.1
Medium
João Pedro Soares de AlcântaraYes
2025-11-06 00:00CVE-2025-64373
8.1
High
João Pedro Soares de AlcântaraYes
2025-09-06 00:00CVE-2025-59012
6.1
Medium
Tran Nguyen Bao KhanhYes
2025-09-06 00:00CVE-2025-59011
5.3
Medium
Tran Nguyen Bao KhanhYes
2025-07-10 00:00CVE-2025-52714
7.5
High
FrankYes
Showing 1–10 of 24 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C