CVE-2026-25449: WordPress Traveler theme < 3.2.8.1 - PHP Object Injection vulnerability
Published Mar 18, 2026
·Updated
Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through < 3.2.8.1.
Affected Software
1 affected component
shinetheme Traveler (WordPress theme)<3.2.8.1
Remediation
Information
Update the WordPress Traveler theme to the latest available version (at least 3.2.8.1).
Event History
Mar 18, 2026
CVE Published
via MITRE·01:12 PM
Data Sourced
via MITRE·01:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25449?
CVE-2026-25449 is classified as a high severity vulnerability due to the potential for PHP Object Injection.
2
How do I fix CVE-2026-25449?
To fix CVE-2026-25449, update the Shinetheme Traveler theme to version 3.2.8.1 or later.
3
What systems are affected by CVE-2026-25449?
CVE-2026-25449 affects versions of the Shinetheme Traveler theme prior to 3.2.8.1.
4
What type of vulnerability is CVE-2026-25449?
CVE-2026-25449 is a PHP Object Injection vulnerability that allows for deserialization of untrusted data.
5
Can CVE-2026-25449 be exploited remotely?
Yes, CVE-2026-25449 can potentially be exploited remotely if the affected theme is in use.