SQL Injection Vulnerability in Traveler Code by NotFound
CVE-2025-22699

9CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
4 February 2025

Summary

An SQL Injection vulnerability exists in Traveler Code due to inadequate neutralization of special elements in SQL commands. This flaw could allow unauthorized users to execute arbitrary SQL queries, potentially compromising sensitive data or affecting the integrity of the application. Affected versions span from n/a to 3.1.0, making it critical for users to update to the latest version to mitigate the risks associated with this vulnerability.

Affected Version(s)

Traveler Code <= 3.1.0

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.