CVE-2025-63028: WordPress Traveler theme <= 3.2.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through <= 3.2.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63028?
CVE-2025-63028 is classified as a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-63028?
To fix CVE-2025-63028, upgrade Shinetheme Traveler to version 3.2.7 or later, which addresses the access control issues.
What systems are affected by CVE-2025-63028?
CVE-2025-63028 affects Shinetheme Traveler versions up to and including 3.2.6.
What is the main issue with CVE-2025-63028?
The main issue with CVE-2025-63028 is the missing authorization vulnerability that allows for incorrectly configured access control security levels.
Can CVE-2025-63028 be exploited remotely?
Yes, CVE-2025-63028 can be exploited remotely if an attacker gains access to the improperly secured functionalities.