
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69030 is an Insecure Direct Object Reference (IDOR) / Authorization Bypass Through User-Controlled Key vulnerability in the Mikado-Themes Backpack Traveler WordPress theme. It affects all versions up to and including 2.10.3, allowing authenticated attackers with low privileges (Subscriber-level) to bypass access controls. The vulnerability was reported on November 29, 2025, by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) and published on December 29–30, 2025. It carries a CVSS v3.1 base score of 5.4 (Medium) (Patchstack).
The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), commonly known as IDOR. The root cause is incorrectly configured access control within the Backpack Traveler WordPress theme, where object references (such as IDs or keys) supplied by the user are not properly validated against the authenticated user's authorization level. An attacker with at least Subscriber-level access can manipulate these user-controlled keys in requests to access or modify resources they should not be permitted to interact with. No public proof-of-concept exploit code has been identified at this time (Patchstack).
Successful exploitation could allow a low-privileged authenticated attacker to bypass authorization controls, potentially accessing sensitive files, folders, or database records belonging to other users or restricted areas of the WordPress site. The integrity and availability impacts are rated low, with no direct confidentiality impact per the CVSS scoring, though IDOR vulnerabilities can expose sensitive data depending on the specific objects accessible. The scope is limited to the affected WordPress installation running the vulnerable theme (Patchstack).
The vulnerability requires low-level authentication (Subscriber role) and no user interaction, making it relatively straightforward to exploit for any registered user on an affected WordPress site. The EPSS score is 0.017% (0.000170), indicating a very low probability of exploitation in the wild at this time. No in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been identified. No official patch is currently available as of the publication date (Patchstack).
As of the disclosure date (December 29, 2025), no official patch is available for the Backpack Traveler theme. Site administrators are advised to monitor the theme's official repository or the WordPress theme directory for an updated version and apply it as soon as one is released. In the interim, consider restricting user registration to trusted individuals, disabling open registration if not required, or using a Web Application Firewall (WAF) with IDOR detection rules. Patchstack users may benefit from virtual patching capabilities offered by the platform (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."