Vulnerabilities > Shinecommerce

DATE CVE VULNERABILITY TITLE RISK
2025-03-15 CVE-2025-1771 PHP Remote File Inclusion vulnerability in Shinecommerce Traveler
The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_load_more_post' function 'style' parameter.
network
low complexity
shinecommerce CWE-98
critical
9.8
2025-03-15 CVE-2025-1773 Cross-site Scripting vulnerability in Shinecommerce Traveler
The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.1.8 due to insufficient input sanitization and output escaping.
network
low complexity
shinecommerce CWE-79
6.1