CVE-2026-22426: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-22426 is an Authorization Bypass Through User-Controlled Key (IDOR) vulnerability in the Elated-Themes Sweet Jane WordPress theme. It allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels. The vulnerability affects Sweet Jane versions up to and including 1.2. It was disclosed on January 22, 2026, by Patchstack, and carries a CVSS v3.1 base score of 5.4 (Medium), assigned by Patchstack (NVD).

Technical details

The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), commonly known as an Insecure Direct Object Reference (IDOR). An attacker can manipulate user-controlled keys or identifiers in requests to access or modify resources they are not authorized to interact with, due to insufficient server-side access control validation in the Sweet Jane theme. Exploitation requires a low-privilege authenticated account (e.g., a subscriber-level WordPress user) and no user interaction, and is achievable over the network with low attack complexity (NVD, Patchstack).

Impact

Successful exploitation can result in limited integrity and availability impacts on the affected WordPress installation. An attacker with a low-privilege account could manipulate object references to modify or disrupt data they would not normally have access to, though confidentiality impact is assessed as none. The scope is limited to the affected system, and there is no evidence of lateral movement potential beyond the WordPress environment (NVD).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.017%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified (NVD).

Mitigation and workarounds

Users of the Sweet Jane WordPress theme by Elated-Themes should update to a version beyond 1.2 if a patched release is available, or remove the theme if no patch has been issued. WordPress site administrators should audit user roles and restrict account registration to trusted users to reduce the attack surface. Monitoring WordPress access logs for unusual requests manipulating object identifiers (e.g., post IDs, user IDs) in theme-related endpoints is also advisable (NVD, Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management