CVE-2026-22400: WordPress Holmes theme <= 1.7 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Holmes holmes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Holmes: from n/a through <= 1.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22400?
CVE-2026-22400 has a medium severity level due to its potential for unauthorized access through incorrect access control configurations.
How do I fix CVE-2026-22400?
To fix CVE-2026-22400, upgrade the Mikado-Themes Holmes theme to a version greater than 1.7 that addresses this vulnerability.
What causes CVE-2026-22400?
CVE-2026-22400 is caused by insecure direct object references that allow users to bypass authorization checks.
Who is affected by CVE-2026-22400?
CVE-2026-22400 affects users of the Mikado-Themes Holmes theme version 1.7 and earlier on WordPress installations.
Is there a workaround for CVE-2026-22400?
A temporary workaround for CVE-2026-22400 includes manually reviewing and tightening access controls for sensitive resources until the theme is updated.