Impact
This vulnerability is a Missing Authorization flaw that enables an attacker to delete content in the shinetheme Traveler WordPress theme without proper access controls. The flaw arises from incorrectly configured access control security levels, allowing removal of posts, pages, or other content. Consequently, an attacker who exploits this issue can cause loss or destruction of user data and disrupt the website’s content integrity.
Affected Systems
The flaw affects any site using the Traveler theme version prior to 3.2.3, released by shinetheme. All installations of the theme where the version number is older than 3.2.3 are susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity risk. The EPSS score of less than 1% suggests low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. A likely attack path involves an authenticated user exploiting the theme’s content management interface through the web UI to delete posts or pages, but the flaw could also be triggered via the REST API if not properly protected. The missing authorization allows the attacker to perform deletion operations that should be restricted to higher‑privileged roles.
OpenCVE Enrichment
EUVD