CVE-2025-67917: WordPress Traveler theme <= 3.2.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through <= 3.2.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67917?
CVE-2025-67917 has a high severity level due to its potential to allow unauthorized access to sensitive functionalities.
How do I fix CVE-2025-67917?
To mitigate CVE-2025-67917, upgrade the Traveler theme to a version later than 3.2.6 where the vulnerability has been patched.
What systems are affected by CVE-2025-67917?
CVE-2025-67917 affects the Traveler theme on WordPress versions up to and including 3.2.6.
What exploits are possible with CVE-2025-67917?
CVE-2025-67917 can be exploited to bypass access controls, allowing unauthorized users to perform actions typically restricted to authorized users.
Is CVE-2025-67917 being actively exploited in the wild?
As of now, there have been reports indicating that CVE-2025-67917 may be targeted by attackers, emphasizing the importance of applying the necessary patches.