
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64371 is a Blind SQL Injection vulnerability in the ShineTheme Traveler WordPress theme, classified under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). It affects all versions of the Traveler theme prior to 3.2.6 and was published on December 18, 2025, with Patchstack as the assigning authority. The vulnerability carries a CVSS v3.1 base score of 8.5 (High), reflecting network-based exploitation with low complexity and low privilege requirements (Feedly, Patchstack).
The vulnerability stems from insufficient input sanitization in the ShineTheme Traveler WordPress theme, where user-supplied data is incorporated into SQL queries without proper neutralization, enabling Blind SQL Injection (CWE-89). Because the injection is "blind," the attacker does not receive direct query output but can infer database contents through boolean-based or time-based inference techniques. Exploitation requires only low-privilege (authenticated) access and no user interaction, and the changed scope indicator suggests the impact can extend beyond the vulnerable component itself — potentially affecting the underlying database and other hosted data (Feedly).
A low-privileged attacker exploiting this vulnerability can extract sensitive information from the WordPress database, including user credentials, personal data, and site configuration, resulting in a high confidentiality impact. There is also a low integrity impact, meaning limited unauthorized modification of database contents is possible. Availability is not directly affected, but successful exploitation could facilitate account takeover or further lateral movement within the hosting environment (Feedly).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.021%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported.
AND SLEEP(5)-- or AND 1=1-- / AND 1=2-- patterns) to confirm the injection point.sqlmap with the identified parameter and session cookie to enumerate databases, tables, and extract sensitive data (e.g., WordPress wp_users table for credentials).', --, SLEEP, BENCHMARK, AND 1=) in query parameters; abnormal response time variations suggesting time-based blind injection probing.SLEEP() or heavy computation functions; anomalous database read activity from the WordPress application user account.The primary remediation is to upgrade the ShineTheme Traveler WordPress theme to version 3.2.6 or later, which addresses the SQL injection vulnerability (Feedly, Patchstack). As interim mitigations, administrators should implement a Web Application Firewall (WAF) with SQL injection rules, apply the principle of least privilege to database accounts used by WordPress, and enable logging of database queries to detect anomalous activity. Parameterized queries and prepared statements should be enforced at the application level for any custom development.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."