CVE-2026-22393: WordPress Curly theme <= 3.3 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Curly curly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Curly: from n/a through <= 3.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22393?
CVE-2026-22393 is classified as a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2026-22393?
To fix CVE-2026-22393, upgrade the Mikado-Themes Curly theme to the latest version or apply specific patches provided by the vendor.
What kind of vulnerability is CVE-2026-22393?
CVE-2026-22393 is an Insecure Direct Object References (IDOR) vulnerability that allows for unauthorized access control.
What versions of the Curly theme are affected by CVE-2026-22393?
CVE-2026-22393 affects all versions of the Mikado-Themes Curly theme up to and including 3.3.
Is CVE-2026-22393 exploitable by unauthenticated users?
Yes, CVE-2026-22393 can be exploited by unauthenticated users due to improper access controls.