CVE-2026-22396: WordPress Fiorello theme <= 1.0 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Fiorello fiorello allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fiorello: from n/a through <= 1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22396?
The severity of CVE-2026-22396 is considered moderate due to its potential for exploitation through insecure direct object references.
How do I fix CVE-2026-22396?
To fix CVE-2026-22396, update the Mikado-Themes Fiorello theme to a version that includes patches for the insecure direct object reference vulnerability.
What systems are affected by CVE-2026-22396?
CVE-2026-22396 affects versions of the Mikado-Themes Fiorello theme up to and including 1.0.
What type of vulnerability is CVE-2026-22396?
CVE-2026-22396 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
Can CVE-2026-22396 lead to unauthorized access?
Yes, CVE-2026-22396 can lead to unauthorized access due to incorrectly configured access controls.