PatchSiren

Adivaha CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Adivaha CVE published 2026-04-09

CVE-2023-54359

CVE-2023-54359 is a time-based blind SQL injection vulnerability in the WordPress adivaha Travel Plugin 2.3. The vulnerability allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pid' GET parameter. Attackers can send requests to the /mobile-app/v3/ endpoint with crafted 'pid' values using XOR-based payloads to extract sensitive database information or cause [truncated]

MEDIUM Adivaha CVE published 2026-04-09

CVE-2023-54358

CVE-2023-54358 is a reflected cross-site scripting vulnerability in the WordPress adivaha Travel Plugin 2.3. The vulnerability allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter at the /mobile-app/v3/ endpoint. This type of vulnerability can lead to the execution of arbitrary code in victims' browsers, potentially resulting in the theft of session tokens or [truncated]