First published: Thu Mar 27 2025(Updated: )
Missing Authorization vulnerability in Shinetheme Traveler.This issue affects Traveler: from n/a through 3.1.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Traveler | <=3.1.8 | |
Traveler | <=3.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26956 is classified as a missing authorization vulnerability which can lead to unauthorized access to sensitive functionalities.
To fix CVE-2025-26956, update the Shinetheme Traveler plugin to the latest version beyond 3.1.8 to ensure appropriate access controls are in place.
CVE-2025-26956 affects Shinetheme Traveler versions up to and including 3.1.8.
Users of Shinetheme Traveler theme versions up to 3.1.8 are at risk due to missing authorization checks.
CVE-2025-26956 is a broken access control vulnerability that allows unauthorized users to perform actions without proper permissions.