CVE-2025-26873: WordPress Traveler theme < 3.2.1 - PHP Object Injection vulnerability
Published Mar 27, 2025
·Updated
Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.
Affected Software
1 affected component
ShineTheme Traveler WordPress theme<3.2.1
Remediation
Information
Update to 3.2.1 or a higher version.
Event History
Mar 27, 2025
CVE Published
via MITRE·09:59 PM
Data Sourced
via MITRE·09:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-26873?
CVE-2025-26873 has been classified as a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-26873?
To fix CVE-2025-26873, you should update the Shinetheme Traveler to the latest version past 3.1.8.
3
Which versions are affected by CVE-2025-26873?
CVE-2025-26873 affects Shinetheme Traveler versions from n/a through 3.1.8.
4
What type of vulnerability is CVE-2025-26873?
CVE-2025-26873 is classified as a deserialization of untrusted data vulnerability.
5
How can CVE-2025-26873 impact my website?
If exploited, CVE-2025-26873 could allow an attacker to execute arbitrary code, potentially compromising your website.