CVE-2026-25449
Travel Booking
Minimum safe version
3.2.8.1
Update to 3.2.8.1 or later to address 33 fixable vulnerabilities
CVE-2026-24367
CVE-2025-67917
CVE-2025-64371
CVE-2025-64372
CVE-2025-64373
CVE-2025-63028
CVE-2025-59011
CVE-2025-59012
CVE-2025-52714
CVE-2025-26733
CVE-2025-26956
CVE-2025-26898
CVE-2025-26873
Traveler <= 3.1.8 - Unauthenticated Local File Inclusion via hotel_alone_load_more_post
Traveler <= 3.1.8 - Reflected Cross-Site Scripting
CVE-2024-12811
CVE-2024-11926
CVE-2024-11912
Travel Booking < 2.8.4 - Unauthenticated Cross-Site Scripting (XSS)
Travel Booking < 2.7.8.4 - Reflected & Stored XSS
Travel Booking < 2.8.4 - Unauthenticated SQL Injection
Travel Booking < 2.8.2 - Unauthenticated Reflected XSS
Travel Booking < 2.7.8.6 - Reflected & Persistent XSS Issues
Travel Booking WordPress Theme < 2.7.8.4 - Cross-Site Scripting
Traveler – Travel Booking WordPress Theme < 2.7.8.6 - Cross-Site Scripting
Travel Booking WordPress Theme < 2.8.2 - Cross-Site Scripting
Traveler – Travel Booking WordPress Theme < 2.8.4 - Cross-Site Scripting
Travel Booking WordPress Theme < 2.8.4 - SQL Injection
WordPress Travel Booking theme <= 2.7.8.3 - Reflected & Stored Cross-Site Scripting (XSS) vulnerabilities
WordPress Travel Booking Theme <= 2.7 - Reflected & Stored Cross-Site Scripting XSS vulnerability
WordPress Travel Booking theme <= 2.7.8.5 - Reflected & Persistent Cross-Site Scripting (XSS) vulnerabilities
WordPress Travel Booking theme <= 2.8.1 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability
WordPress Travel Booking theme <= 2.8.3 - Unauthenticated Cross-Site Scripting (XSS) vulnerability
WordPress Travel Booking theme <= 2.8.3 - Unauthenticated SQL Injection (SQLi) vulnerability