CVE-2026-22409: WordPress Justicia theme <= 1.2 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Justicia justicia allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Justicia: from n/a through <= 1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22409?
CVE-2026-22409 is categorized as a high-severity vulnerability due to its potential for authorization bypass.
How can I fix CVE-2026-22409?
To fix CVE-2026-22409, update the Mikado-Themes Justicia theme to version 1.2 or higher, ensuring proper access control configurations.
What specific issue does CVE-2026-22409 present?
CVE-2026-22409 presents an Insecure Direct Object References (IDOR) vulnerability that allows unauthorized access through improperly set security levels.
Who is affected by CVE-2026-22409?
CVE-2026-22409 affects users of the Mikado-Themes Justicia theme version 1.2 and earlier on WordPress.
Is CVE-2026-22409 actively being exploited?
There is no public information confirming active exploitation of CVE-2026-22409, but vulnerabilities of this nature are commonly targeted.