cvemon logocvemon logo

Activity

Trending

CVE-2025-26873

Published Mar 27, 2025

Last updated 16 days ago

CVSS critical 9.0
  1. Overview

  2. Scores

  3. Weaknesses

  4. Social media

  5. References

Overview

Description
Deserialization of Untrusted Data vulnerability in Shine theme Traveler.This issue affects Traveler: from n/a before 3.2.1.
Source
audit@patchstack.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9
Impact score
6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

audit@patchstack.com
CWE-502

Social media

Hype score
Not currently trending
  1. Critical RCE vulnerability (CVE-2025-26873) found in Shinetheme Traveler WordPress theme (≤3.1.8). No patch yet - attackers can execute code remotely. Check if you're affected and apply mitigations now. Details: https://t.co/0dTr5SXGxh

    @RedTeamNewsBlog

    28 Mar 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. [CVE-2025-26873: CRITICAL] Deserialization of Untrusted Data vulnerability in Shinetheme Traveler.This issue affects Traveler: from n/a through 3.1.8.#cybersecurity,#vulnerability https://t.co/oIFdaypHfp https://t.co/vXNshtTipN

    @CveFindCom

    27 Mar 2025

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.

  • https://nvd.nist.gov/vuln/detail/CVE-2025-26873
  • https://patchstack.com/database/wordpress/theme/traveler/vulnerability/wordpress-traveler-theme-3-1-8-php-object-injection-vulnerability?_s_id=cve
TRY INTRUDER
Intruder logo

© 2025 Intruder Systems Ltd.

AboutPrivacySitemapFeeds