
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24367 is a Blind SQL Injection vulnerability in the ShineTheme Traveler WordPress theme, classified under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). It affects all versions of the Traveler theme prior to 3.2.8 and was disclosed on January 22, 2026, by Patchstack, with credit to researcher João Pedro S Alcântara (Kinorth), who reported it on December 23, 2025. The vulnerability carries a CVSS v3.1 base score of 8.5 (High), as assigned by Patchstack (Patchstack).
The vulnerability stems from insufficient sanitization of user-supplied input passed into SQL queries within the ShineTheme Traveler WordPress theme, allowing an authenticated attacker with low privileges (Contributor or Developer level) to inject malicious SQL syntax (CWE-89). The attack is network-based, requires no user interaction, and operates with a changed scope — meaning the impact extends beyond the vulnerable component itself. Because it is a blind SQL injection, the attacker infers database content through differential application responses rather than direct error output, using techniques such as boolean-based or time-based inference (Patchstack).
Successful exploitation allows an authenticated low-privileged attacker to extract sensitive data from the WordPress database — including user credentials, personal information, and site configuration — and potentially modify database contents. The changed scope in the CVSS vector indicates that impacts can extend beyond the Traveler theme itself to the broader WordPress installation and underlying database. Availability may also be partially disrupted, though the primary risk is high-impact confidentiality loss (Patchstack).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (Patchstack). The EPSS score is approximately 0.021%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity.
inurl:wp-content/themes/traveler).' AND SLEEP(5)-- or ' AND 1=1--) into the vulnerable parameter to confirm exploitability via differential response times or behavior.sqlmap with the identified injectable parameter to enumerate the database schema, extract WordPress user table credentials (including hashed passwords), and retrieve other sensitive data.', --, SLEEP, WAITFOR, AND 1=1) in query parameters; abnormal response time variations suggesting time-based blind SQL injection.SLEEP(), BENCHMARK(), or boolean conditions not typical of normal theme operation.The primary remediation is to upgrade the ShineTheme Traveler WordPress theme to version 3.2.8 or later, which contains the fix for this vulnerability (Patchstack). As interim measures, administrators should restrict the number of accounts with Contributor or higher privileges, implement a Web Application Firewall (WAF) with SQL injection detection rules, and monitor database query logs for anomalous patterns. Sites unable to update immediately should consider using Patchstack's virtual patching capability or a similar WAF solution to block exploitation attempts.
Wordfence included CVE-2026-24367 in its weekly WordPress vulnerability report for the period of January 19–25, 2026, highlighting it among notable disclosures (Wordfence Blog). The vulnerability was also noted by TheHackerWire on social platforms including Bluesky and Mastodon. Community reaction has been measured, with Patchstack classifying it as low priority due to the authentication requirement, though noting the class of vulnerability is commonly leveraged in mass WordPress exploit campaigns.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."