---
id: CVE-2023-54359
title: >-
  WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection
  vulnerability that allows unauthenticated attackers to manipulate database
  queries by injecting SQL code through the 'pid' GET parameter
summary: >-
  WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection
  vulnerability that allows unauthenticated attackers to manipulate database
  queries by injecting SQL code through the 'pid' GET parameter. Attackers can
  send re…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-89
published: '2026-04-09'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T23:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-54359'
references:
  - url: 'https://wordpress.org/plugins/adiaha-hotel/'
    label: disclosure@vulncheck.com
  - url: 'https://www.adivaha.com/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/51655'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wordpress-adivaha-travel-plugin-sql-injection-via-pid
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00269
epssPercentile: 0.17135
ingestedAt: '2026-09-26T23:39:28.805Z'
---

## Overview

WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pid' GET parameter. Attackers can send requests to the /mobile-app/v3/ endpoint with crafted 'pid' values using XOR-based payloads to extract sensitive database information or cause denial of service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
