
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67917 is a Missing Authorization (Broken Access Control) vulnerability in the shinetheme Traveler WordPress theme that allows attackers to exploit incorrectly configured access control security levels. It affects Traveler versions up to and including 3.2.6, with version 3.2.7 being the patched release. The vulnerability was reported by Rafie Muhammad on October 15, 2025, and published by Patchstack on January 5–8, 2026. The CNA (Patchstack) assigned a CVSS v3.1 score of 6.5 (Medium), while an earlier CISA-ADP assessment scored it 8.1 (High) — the current authoritative score from Patchstack is 6.5 (Patchstack, NVD).
The vulnerability is classified as CWE-862 (Missing Authorization), falling under OWASP Top 10 category A1: Broken Access Control. The flaw stems from the absence of proper authorization, authentication, or nonce token checks in one or more functions within the Traveler WordPress theme, allowing an unprivileged user to invoke higher-privileged actions. The attack is network-accessible, requires no user interaction, and — per the updated Patchstack assessment — can be exploited without any authentication. No public proof-of-concept code has been disclosed (Patchstack, NVD).
Successful exploitation can lead to unauthorized access to protected functionality within WordPress sites running the Traveler theme. Depending on the specific unprotected function, attackers may be able to disclose sensitive data or modify site content and configuration without proper authorization. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or traffic (Patchstack).
There is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.017%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as moderately dangerous and notes that broken access control vulnerabilities of this type are frequently leveraged in automated mass-exploit campaigns against WordPress sites (Patchstack, NVD).
The primary remediation is to update the Traveler WordPress theme to version 3.2.7 or later, which contains the fix for this vulnerability. Patchstack has also issued a virtual patching/mitigation rule for subscribers that blocks exploitation attempts until the theme is updated. Site administrators unable to update immediately should consider restricting access to the WordPress admin area and monitoring for unusual activity from unauthenticated or low-privileged users (Patchstack).
The vulnerability received brief coverage on social media platforms including Mastodon (via TheHackerWire) shortly after disclosure in January 2026. No significant vendor statements or notable researcher commentary beyond the Patchstack advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."