CVE-2025-26956: WordPress Traveler theme < 3.2.1 - Broken Access Control vulnerability
Published Mar 27, 2025
·Updated
Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.
Affected Software
1 affected component
shinetheme Traveler (WordPress theme)<3.2.1
Event History
Mar 27, 2025
CVE Published
via MITRE·09:49 PM
Data Sourced
via MITRE·09:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-26956?
CVE-2025-26956 is classified as a missing authorization vulnerability which can lead to unauthorized access to sensitive functionalities.
2
How do I fix CVE-2025-26956?
To fix CVE-2025-26956, update the Shinetheme Traveler plugin to the latest version beyond 3.1.8 to ensure appropriate access controls are in place.
3
What versions are affected by CVE-2025-26956?
CVE-2025-26956 affects Shinetheme Traveler versions up to and including 3.1.8.
4
Who is impacted by CVE-2025-26956?
Users of Shinetheme Traveler theme versions up to 3.1.8 are at risk due to missing authorization checks.
5
What kind of vulnerability is CVE-2025-26956?
CVE-2025-26956 is a broken access control vulnerability that allows unauthorized users to perform actions without proper permissions.