CVE-2025-59012: WordPress Traveler theme < 3.2.3 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Traveler allows Reflected XSS. This issue affects Traveler: from n/a through n/a.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Traveler traveler allows Reflected XSS.This issue affects Traveler: from n/a through < 3.2.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59012?
CVE-2025-59012 is classified as a medium severity vulnerability due to its potential impact on user data and site integrity.
How do I fix CVE-2025-59012?
To remediate CVE-2025-59012, update the Traveler theme to the latest version available and ensure all user inputs are properly sanitized.
What types of attacks are possible due to CVE-2025-59012?
CVE-2025-59012 allows attackers to perform reflected Cross-site Scripting (XSS) attacks, which can lead to data theft or unauthorized actions on behalf of users.
Is my site at risk if I use an unpatched version of the Traveler theme related to CVE-2025-59012?
Yes, using an unpatched version of the Traveler theme puts your site at risk of reflected XSS attacks as indicated by CVE-2025-59012.
What versions of the Traveler theme are affected by CVE-2025-59012?
CVE-2025-59012 affects the Traveler theme up to and including version 3.2.3.