← WordPress Vulnerabilities
WordPress security by component

WP Travel Gutenberg Blocks

WP Travel Gutenberg Blocks is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jun 17, 2026; the highest CVE/CNA score is 9.3.

Plugin slug: wp-travel-blocks

CVE-2026-54808: WP Travel Gutenberg Blocks: SQL injection

WP Travel Gutenberg Blocks is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 3.9.4.

PublishedJun 17, 2026
Known safe version3.9.5
Safe version
Jun 17, 2026 CVE-2026-54808
WP Travel Gutenberg Blocks: SQL injection
WP Travel Gutenberg Blocks is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 3.9.4.
3.9.5
CVE9.3
NVDPending
Oct 22, 2025 CVE-2025-62063
WP Travel Gutenberg Blocks: Cross-site scripting
WP Travel Gutenberg Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Aug 20, 2025 CVE-2025-53207
WP Travel Gutenberg Blocks: Filesystem traversal
WP Travel Gutenberg Blocks is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.1
NVDPending
Oct 05, 2024 CVE-2024-47627
WP Travel Gutenberg Blocks: Cross-site scripting
WP Travel Gutenberg Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Aug 18, 2024 CVE-2024-43284
WP Travel Gutenberg Blocks: Cross-site scripting
WP Travel Gutenberg Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending