CVE-2026-74020: WordPress Koji theme <= 2.2.1 - Broken Access Control vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.
Affected Software
1 affected component
WordPress Koji theme<=2.2.1
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges to exploit an affected Koji installation.
2
Which installations are affected?
Koji theme versions 2.2.1 and earlier are identified as affected. The provided information does not specify configuration-dependent prerequisites.
3
What is the potential impact?
The reported CVSS vector indicates high confidentiality impact, with no reported integrity or availability impact. Exploitation is network-accessible, requires low attack complexity, and does not require user interaction.