CVE-2025-69030: WordPress Backpack Traveler theme <= 2.10.3 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backpack Traveler: from n/a through <= 2.10.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69030?
CVE-2025-69030 is classified as a critical vulnerability due to its potential for authorization bypass.
How do I fix CVE-2025-69030?
To mitigate CVE-2025-69030, you should update the Backpack Traveler theme to version 2.10.4 or later.
What does CVE-2025-69030 affect?
CVE-2025-69030 affects the Backpack Traveler theme for WordPress, specifically versions up to and including 2.10.3.
What is an authorization bypass in CVE-2025-69030?
Authorization bypass in CVE-2025-69030 allows users to gain unauthorized access to restricted features due to incorrectly configured access controls.
Can CVE-2025-69030 be exploited easily?
Yes, CVE-2025-69030 can be exploited with relative ease if the affected theme version is in use, allowing attackers to bypass security.