Input validation vulnerability in Travel Booking WordPress Theme 3.1.6

The Travel Booking WordPress Theme for WordPress has a security issue called blind time-based SQL Injection. This means that someone could add extra queries to the existing ones, which could allow them to access private information from the website’s database. This is possible because the ‘order_id’ parameter was not properly protected and the SQL query was not carefully prepared. This vulnerability exists in all versions up to and including 3.1.6.

Detected in:

Travel Booking WordPress Theme fixed vulnerable versions: >= * <= 3.1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.