CVE-2026-22407: WordPress Roam theme <= 2.1.1 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Roam roam allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Roam: from n/a through <= 2.1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22407?
CVE-2026-22407 is classified as a medium severity vulnerability due to its potential for unauthorized access to protected resources.
How do I fix CVE-2026-22407?
To fix CVE-2026-22407, update the Mikado-Themes Roam theme to version 2.1.2 or later where this issue is resolved.
Who is affected by CVE-2026-22407?
CVE-2026-22407 affects users of the Mikado-Themes Roam theme versions up to 2.1.1.
What kind of vulnerability is CVE-2026-22407?
CVE-2026-22407 is an Insecure Direct Object References (IDOR) vulnerability that allows authorization bypass.
Can CVE-2026-22407 be exploited remotely?
Yes, CVE-2026-22407 can be exploited remotely by an attacker who can craft requests to access unauthorized resources.