Impact
A missing authorization check in the shinetheme Traveler theme allows users lacking proper privileges to gain access to previously protected administrative functions. An attacker exploiting this flaw could edit or delete content, change theme settings, or otherwise alter site configuration, thereby compromising the site’s confidentiality, integrity, and availability.
Affected Systems
All installations of the Traveler theme from its earliest release through any version prior to 3.2.1 are affected. The vulnerability applies to every pre‑3.2.1 distribution distributed by shinetheme.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector is a publicly accessible WordPress administrative or theme URL that the attacker could exploit. The CVSS score of 7.6 signifies high severity, while an EPSS score of less than 1% indicates a low current exploitation probability. The flaw does not appear in the CISA KEV catalog. The vulnerability is remote; the attacker could perform unauthorized actions and modify site data. No public exploits have been reported, so the practical risk hinges on the site’s exposure and role configuration.
OpenCVE Enrichment
EUVD