CVE-2026-22404: WordPress Innovio theme <= 1.7 - Insecure Direct Object References (IDOR) vulnerability
Published Jan 22, 2026
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Innovio innovio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Innovio: from n/a through <= 1.7.
Affected Software
2 affected components
Mikado-Themes Innovio<=1.7
wordpress/innovio<=1.7
Event History
Jan 22, 2026
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-22404?
CVE-2026-22404 is classified as a medium severity vulnerability due to the risk of unauthorized access.
2
How do I fix CVE-2026-22404?
To fix CVE-2026-22404, update the Mikado-Themes Innovio theme to version 1.8 or later.
3
What type of vulnerability is CVE-2026-22404?
CVE-2026-22404 is an Insecure Direct Object Reference (IDOR) vulnerability that allows for authorization bypass.
4
What versions of Innovio are affected by CVE-2026-22404?
CVE-2026-22404 affects the Innovio theme versions 1.7 and earlier.
5
Who is impacted by CVE-2026-22404?
Users of the Mikado-Themes Innovio theme for WordPress who have not updated past version 1.7 are impacted by CVE-2026-22404.