CVE-2026-22406: WordPress Overton theme <= 1.3 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Overton overton allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Overton: from n/a through <= 1.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22406?
CVE-2026-22406 is classified as a medium severity vulnerability due to its potential for unauthorized access to sensitive information.
How do I fix CVE-2026-22406?
To fix CVE-2026-22406, upgrade the Overton theme to version 1.4 or later which addresses the insecure direct object references issues.
What kind of vulnerability is CVE-2026-22406?
CVE-2026-22406 is an Insecure Direct Object References (IDOR) vulnerability that allows bypassing access controls.
Is CVE-2026-22406 present in all versions of Overton theme?
CVE-2026-22406 affects all versions of the Overton theme up to and including version 1.3.
Who is affected by CVE-2026-22406?
Users and website administrators using the Mikado-Themes Overton theme version 1.3 or earlier are affected by CVE-2026-22406.