Impact
The flaw is a missing authorization check in the Traveler theme, classified as CWE-862. Because of this, users without proper privileges may access endpoints that should be restricted, potentially exposing or altering data managed by the theme.
Affected Systems
The affected product is the Traveler theme developed by Shinetheme. All releases from the earliest available version up through any version before 3.2.1 are impacted.
Risk and Exploitability
The CVSS score of 8.2 categorizes it as high severity, and the EPSS score of less than 1% indicates a very low but nonzero current exploitation probability. The vulnerability is not the subject of CISA’s KEV catalog, suggesting no widespread exploitation recorded. The likely attack vector is web-based: an attacker could target the theme’s endpoints without prior authentication, based on the description that the bug is due to a missing authorization check.
OpenCVE Enrichment
EUVD