CVE-2026-22430: WordPress Verdure theme <= 1.6 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Verdure verdure allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Verdure: from n/a through <= 1.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22430?
CVE-2026-22430 is classified as a critical vulnerability due to its ability to bypass access controls.
How do I fix CVE-2026-22430?
To fix CVE-2026-22430, upgrade the Mikado-Themes Verdure theme to version 1.7 or later.
What is an Insecure Direct Object Reference in CVE-2026-22430?
An Insecure Direct Object Reference occurs when a web application exposes a reference to an internal implementation object, enabling unauthorized access to resources.
Who is affected by CVE-2026-22430?
All users of the Mikado-Themes Verdure theme version 1.6 and earlier are affected by CVE-2026-22430.
What are the potential risks associated with CVE-2026-22430?
The risks include unauthorized access to sensitive user data or functionality due to inadequate access controls.