Shinetheme Traveler WordPress Theme Missing Authorization Vulnerability Allowing Arbitrary Content Deletion

Vulnerability

A missing authorization vulnerability exists in the Shinetheme Traveler WordPress theme, versions prior to 3.2.3. This vulnerability allows for arbitrary content deletion, enabling unauthorized users to remove posts, pages, or media from affected websites.

Impact

Exploitation of this vulnerability could lead to unauthorized deletion of content, such as posts, pages, or media files, from the WordPress site.

Remediation

Users are advised to update the Shinetheme Traveler WordPress theme to version 3.2.3 or later. Patchstack has also issued a virtual patch to block attacks targeting this vulnerability.

Added: Sep 26, 2025, 10:12 AM
Updated: Sep 26, 2025, 3:39 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.