CVE-2025-67917
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67917 is a Missing Authorization (Broken Access Control) vulnerability in the shinetheme Traveler WordPress theme that allows attackers to exploit incorrectly configured access control security levels. It affects Traveler versions up to and including 3.2.6, with version 3.2.7 being the patched release. The vulnerability was reported by Rafie Muhammad on October 15, 2025, and published by Patchstack on January 5–8, 2026. The CNA (Patchstack) assigned a CVSS v3.1 score of 6.5 (Medium), while an earlier CISA-ADP assessment scored it 8.1 (High) — the current authoritative score from Patchstack is 6.5 (Patchstack, NVD).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization), falling under OWASP Top 10 category A1: Broken Access Control. The flaw stems from the absence of proper authorization, authentication, or nonce token checks in one or more functions within the Traveler WordPress theme, allowing an unprivileged user to invoke higher-privileged actions. The attack is network-accessible, requires no user interaction, and — per the updated Patchstack assessment — can be exploited without any authentication. No public proof-of-concept code has been disclosed (Patchstack, NVD).

Impact

Successful exploitation can lead to unauthorized access to protected functionality within WordPress sites running the Traveler theme. Depending on the specific unprotected function, attackers may be able to disclose sensitive data or modify site content and configuration without proper authorization. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or traffic (Patchstack).

Exploitability

There is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.017%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as moderately dangerous and notes that broken access control vulnerabilities of this type are frequently leveraged in automated mass-exploit campaigns against WordPress sites (Patchstack, NVD).

Mitigation and workarounds

The primary remediation is to update the Traveler WordPress theme to version 3.2.7 or later, which contains the fix for this vulnerability. Patchstack has also issued a virtual patching/mitigation rule for subscribers that blocks exploitation attempts until the theme is updated. Site administrators unable to update immediately should consider restricting access to the WordPress admin area and monitoring for unusual activity from unauthenticated or low-privileged users (Patchstack).

Community reactions

The vulnerability received brief coverage on social media platforms including Mastodon (via TheHackerWire) shortly after disclosure in January 2026. No significant vendor statements or notable researcher commentary beyond the Patchstack advisory have been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management