
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22426 is an Authorization Bypass Through User-Controlled Key (IDOR) vulnerability in the Elated-Themes Sweet Jane WordPress theme. It allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels. The vulnerability affects Sweet Jane versions up to and including 1.2. It was disclosed on January 22, 2026, by Patchstack, and carries a CVSS v3.1 base score of 5.4 (Medium), assigned by Patchstack (NVD).
The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), commonly known as an Insecure Direct Object Reference (IDOR). An attacker can manipulate user-controlled keys or identifiers in requests to access or modify resources they are not authorized to interact with, due to insufficient server-side access control validation in the Sweet Jane theme. Exploitation requires a low-privilege authenticated account (e.g., a subscriber-level WordPress user) and no user interaction, and is achievable over the network with low attack complexity (NVD, Patchstack).
Successful exploitation can result in limited integrity and availability impacts on the affected WordPress installation. An attacker with a low-privilege account could manipulate object references to modify or disrupt data they would not normally have access to, though confidentiality impact is assessed as none. The scope is limited to the affected system, and there is no evidence of lateral movement potential beyond the WordPress environment (NVD).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.017%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified (NVD).
Users of the Sweet Jane WordPress theme by Elated-Themes should update to a version beyond 1.2 if a patched release is available, or remove the theme if no patch has been issued. WordPress site administrators should audit user roles and restrict account registration to trusted users to reduce the attack surface. Monitoring WordPress access logs for unusual requests manipulating object identifiers (e.g., post IDs, user IDs) in theme-related endpoints is also advisable (NVD, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."