CVE-2026-22411: WordPress Dolcino theme <= 1.6 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Dolcino dolcino allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dolcino: from n/a through <= 1.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22411?
CVE-2026-22411 is classified as a security vulnerability that involves insecure direct object references, leading to potential authorization bypass.
How do I fix CVE-2026-22411?
To fix CVE-2026-22411, update the Mikado-Themes Dolcino theme to version 1.7 or higher where the vulnerability has been addressed.
What impact does CVE-2026-22411 have on my website?
The impact of CVE-2026-22411 could allow unauthorized users to access restricted resources on your website.
Who is affected by CVE-2026-22411?
CVE-2026-22411 affects users of the Mikado-Themes Dolcino theme version 1.6 and prior.
Is CVE-2026-22411 actively being exploited?
While there are no reported instances of active exploitation for CVE-2026-22411, it is advisable to patch the vulnerability promptly.