CVE-2025-67917

WordPress Traveler theme <= 3.2.6 - Broken Access Control vulnerability

Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through <= 3.2.6.


We have discovered 1,511 live websites that are affected by CVE-2025-67917.

Run a Free Instant Scan




Affected Software

Product  Traveler
Category Wordpress Themes
Vulnerable Domains1,511 live websites (100% of Traveler install base)
Vulnerable Versions
  • from 0 through 3.2.6
Vulnerable Versions Count5 versions ( 100% of all versions)



Details

  • Published - Jan 8, 2026
  • Updated - Jan 20, 2026

Credits

  • Rafie Muhammad (Patchstack) (finder)

Website Distribution by Country

Number of websites using CVE-2025-67917
United States397 websites



Germany123 websites
Cyprus117 websites
India95 websites
Italy69 websites
Vietnam66 websites
Greece50 websites
Spain42 websites
GB42 websites
France37 websites

Website Distribution by TLD

Number of websites using CVE-2025-67917
.com984 websites
.it43 websites
.net34 websites
.ru18 websites
.com.br13 websites
.nl13 websites
.es12 websites
.org12 websites
.co.uk12 websites
.de12 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-67917

Top websites that are affected by CVE-2025-67917. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.com India***,***
*************.hr Croatia***,***
******************.de Belgium***,***
****************.org United States***,***
***************.com Cyprus***,***
*************.com Portugal***,***
*****.**********.com United States***,***
***.de Germany*,***,***
******.**********.com United States*,***,***
*****.rest Ukraine*,***,***
See full domain list

FAQ

A total of 1,511 websites have been identified as vulnerable to CVE-2025-67917, based on global website indexing conducted by WebTechSurvey.
The Traveler is affected by the CVE-2025-67917 vulnerability.
Traveler versions up to and including 3.2.6 are vulnerable to CVE-2025-67917.