Description
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backpack Traveler: from n/a through <= 2.10.3.
Published: 2025-12-30
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Backpack Traveler theme contains an IDOR flaw that permits users to modify a controlled key value in HTTP requests. This flaw enables attackers to read or manipulate data belonging to other users or system resources, effectively bypassing intended access controls. The weakness is classified as CWE-639, indicating that user-supplied input influences authorization decisions. The impact is limited to the integrity and confidentiality of content managed by the theme and does not directly compromise the underlying WordPress core or database servers.

Affected Systems

The affected product is the Mikado-Themes Backpack Traveler theme for WordPress, with all releases up to and including version 2.10.3 susceptible to the vulnerability. The theme is discovered on WordPress installations that have not been upgraded beyond this version. No other WordPress core or plugin versions are implicated by the current data.

Risk and Exploitability

The CVSS score of 5.4 represents moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation under current public threat intelligence, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is remote, with an authenticated or potentially unauthenticated user able to craft URLs containing permissible resource identifiers. Exploitation requires that the attacker has sufficient knowledge of the site’s internal resource identifiers and that the theme’s access controls are not otherwise overridden by site owners.

Generated by OpenCVE AI on April 29, 2026 at 14:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Backpack Traveler theme to a version newer than 2.10.3, which includes a fix for the IDOR issue.
  • Verify that only authorized users have permission to edit or view theme‑controlled sections, applying the principle of least privilege to all related menu options.
  • As a temporary measure, disable or restrict direct access to the theme’s administrative endpoints or enforce stricter authentication checks for requests that include user‑controlled keys.

Generated by OpenCVE AI on April 29, 2026 at 14:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Thu, 29 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Qodeinteractive
Qodeinteractive backpack Traveler
CPEs cpe:2.3:a:qodeinteractive:backpack_traveler:*:*:*:*:*:wordpress:*:*
Vendors & Products Qodeinteractive
Qodeinteractive backpack Traveler

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Mikado-themes
Mikado-themes backpack Traveler
Wordpress
Wordpress wordpress
Vendors & Products Mikado-themes
Mikado-themes backpack Traveler
Wordpress
Wordpress wordpress

Fri, 02 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backpack Traveler: from n/a through <= 2.10.3.
Title WordPress Backpack Traveler theme <= 2.10.3 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References

Subscriptions

Mikado-themes Backpack Traveler
Qodeinteractive Backpack Traveler
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:34.790Z

Reserved: 2025-12-29T11:18:35.617Z

Link: CVE-2025-69030

cve-icon Vulnrichment

Updated: 2026-01-02T22:01:17.301Z

cve-icon NVD

Status : Modified

Published: 2025-12-30T11:16:01.590

Modified: 2026-04-27T20:16:25.930

Link: CVE-2025-69030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T15:00:13Z

Weaknesses