Untriaged
Permalink
CVE-2026-22407
5.4 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): NONE
by @fricklerhandwerk Activity log
- Created automatic suggestion
- @fricklerhandwerk added maintainer @fricklerhandwerk maintainer.add
WordPress Roam theme <= 2.1.1 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Roam roam allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Roam: from n/a through <= 2.1.1.
References
Affected products
roam
- =<<= 2.1.1
Matching in nixpkgs
pkgs.geteduroam
GUI client to configure eduroam
pkgs.roam-research
Note-taking tool for networked thought
pkgs.geteduroam-cli
CLI client to configure eduroam
Package maintainers
-
@manyinsects liv <shadows@with.al>
-
@MarchCraft Felix Nilles <felix@dienilles.de>
-
@pbsds Peder Bergebakken Sundt <pbsds@hotmail.com>
-
@viperML Fernando Ayats <ayatsfer@gmail.com>
-
@dbalan Dhananjay Balan <nix@dbalan.in>
Additional maintainers
-
@fricklerhandwerk Valentin Gagarin <valentin@fricklerhandwerk.de>