Input validation vulnerability in Grand Tour | Travel Agency WordPress 5.5.1

The Travel Agency WordPress theme called “The Grand Tour” has a security vulnerability that allows attackers to inject a PHP Object through untrusted input. This can be done by anyone without needing to login. There is no known way to exploit this vulnerability, but if the target system has an additional plugin or theme installed with a POP chain, the attacker could potentially delete files, access sensitive information, or run malicious code.

Detected in:

Grand Tour | Travel Agency WordPress open vulnerable versions: >= * <= 5.5.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.