Input validation vulnerability in Travel Booking WordPress Theme 2.8.4

The Travel Booking WordPress Theme, which is used with the WordPress platform, is vulnerable to a type of attack called blind SQL Injection. This vulnerability affects versions of the theme up to, and including, version 2.8.3. It occurs because the theme does not properly escape user supplied parameters, and does not adequately prepare existing SQL queries. This means that an unauthenticated attacker can add extra SQL queries to an existing query in order to access sensitive information stored in the database.

Detected in:

Travel Booking WordPress Theme fixed vulnerable versions: >= * < 2.8.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.