← WordPress Vulnerabilities
WordPress security by component

Traveler

Traveler is a WordPress component with 17 published CVE records in this archive. The latest tracked vulnerability was published Mar 18, 2026; the highest CVE/CNA score is 9.8.

Theme slug: traveler

CVE-2026-25449: Traveler: Code execution

Traveler is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.

PublishedMar 18, 2026
Safe version guidanceSee mitigation notes
Safe version
Mar 18, 2026 CVE-2026-25449
Traveler: Code execution
Traveler is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending
Jan 22, 2026 CVE-2026-24367
Traveler: SQL injection
Traveler is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Jan 08, 2026 CVE-2025-67917
Traveler: A security weakness
Traveler is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Dec 18, 2025 CVE-2025-64373
Traveler: Filesystem traversal
Traveler is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.1
NVDPending
Dec 18, 2025 CVE-2025-64372
Traveler: Cross-site scripting
Traveler is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Dec 18, 2025 CVE-2025-64371
Traveler: SQL injection
Traveler is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Dec 09, 2025 CVE-2025-63028
Traveler: A security weakness
Traveler is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Sep 26, 2025 CVE-2025-59012
Traveler: Cross-site scripting
Traveler is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Sep 26, 2025 CVE-2025-59011
Traveler: A security weakness
Traveler is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Jul 16, 2025 CVE-2025-52714
Traveler: SQL injection
Traveler is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.3
NVDPending
Mar 27, 2025 CVE-2025-26956
Traveler: A security weakness
Traveler is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.6
NVDPending
Mar 27, 2025 CVE-2025-26898
Traveler: SQL injection
Traveler is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.3
NVDPending
Mar 27, 2025 CVE-2025-26873
Traveler: Code execution
Traveler is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.0
NVDPending
Mar 27, 2025 CVE-2025-26733
Traveler: A security weakness
Traveler is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.2
NVDPending
Mar 15, 2025 CVE-2025-1773
Traveler: Cross-site scripting
Traveler is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Mar 15, 2025 CVE-2025-1771
Traveler: Filesystem traversal
Traveler is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE9.8
NVDPending
Feb 28, 2025 CVE-2024-12811
Traveler: Filesystem traversal
Traveler is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVDPending