CVE-2025-26733: WordPress Traveler theme < 3.2.1 - Broken Access Control vulnerability
Published Mar 27, 2025
·Updated
Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.
Affected Software
1 affected component
ShineTheme Traveler WordPress theme<3.2.1
Event History
Mar 27, 2025
CVE Published
via MITRE·10:01 PM
Data Sourced
via MITRE·10:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-26733?
CVE-2025-26733 is classified as a missing authorization vulnerability in the Shinetheme Traveler, which can lead to unauthorized access.
2
How do I fix CVE-2025-26733?
To fix CVE-2025-26733, update the Shinetheme Traveler to a version beyond 3.1.8 to ensure proper access controls are in place.
3
What versions are affected by CVE-2025-26733?
CVE-2025-26733 affects Traveler versions from n/a through 3.1.8.
4
What should I do if I cannot update to fix CVE-2025-26733?
If unable to update, consider implementing additional security measures such as access control lists or monitoring to mitigate unauthorized access.
5
How can I determine if my site is vulnerable to CVE-2025-26733?
You can determine if your site is vulnerable to CVE-2025-26733 by checking if you are using the Shinetheme Traveler theme version 3.1.8 or earlier.