Impact
The vulnerability is a missing authorization flaw in the shinetheme Traveler theme that allows an attacker to exercise functions or data that should be restricted. Because the theme does not enforce proper security levels, an attacker can potentially compromise sensitive settings, create or modify high‑privilege accounts, or otherwise gain unauthorized access to content. This weakness is identified as CWE‑862.
Affected Systems
WordPress installations that use the Traveler theme version 3.2.6 or earlier are affected. The issue is specific to the Traveler theme distributed by shinetheme and applies to any WordPress site that has not upgraded beyond the stated version.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% shows that the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to identify and access the theme’s privileged endpoints, which is likely possible over the web interface. Because the flaw involves missing authorization, the attack vector is inferred to be remote through the WordPress site, with an attacker needing some level of authenticated access or access to specific URLs related to the theme’s management functions.
OpenCVE Enrichment