Description
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through <= 1.3.
Published: 2026-02-20
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass (IDOR) that can expose or modify protected content
Action: Update theme
AI Analysis

Impact

The documented weakness is an Insecure Direct Object Reference (IDOR), also known as Authorization Bypass Through User‐Controlled Key, which is classified as CWE‑639. An attacker who can manipulate request parameters may be able to access or alter content that should be restricted to specific users. The impact is the unauthorized disclosure or modification of data, potentially compromising confidentiality and integrity of the WordPress site. No indication that the flaw leads to execution of arbitrary code, denial of service, or system compromise.

Affected Systems

The vulnerable component is the Mikado‑Themes PawFriends – Pet Shop and Veterinary WordPress Theme. All releases from the initial launch through version 1.3 are affected, meaning any site using this theme on or before that version could be subject to the IDOR flaw. There is no evidence that newer releases (1.4 and up) contain the fix, but those versions are assumed to be unaffected.

Risk and Exploitability

The CVSS score of 7.5 places the vulnerability in the high range, while the EPSS score of less than 1 % indicates a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The most likely attack vector is web‑based, through manipulation of URLs or form inputs that reference privileged content. Exploits would require that the attacker has some level of web access to the site—either as a normal user or via the administrative interface where the indirect references are used. No special pre‑conditions beyond the presence of the vulnerable theme are documented, so any publicly accessible WordPress instance with the affected theme is at risk.

Generated by OpenCVE AI on April 28, 2026 at 17:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update PawFriends theme to a version above 1.3 or apply vendor patch.
  • Restrict or disable unauthorized users from accessing the theme’s admin panels by implementing role‑based access controls or .htaccess restrictions.
  • Enable audit logging and monitor for suspicious content‑alteration attempts, setting alerts for unauthorized edit actions.

Generated by OpenCVE AI on April 28, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 26 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mikado-themes
Mikado-themes pawfriends - Pet Shop And Veterinary Wordpress Theme
Wordpress
Wordpress wordpress
Vendors & Products Mikado-themes
Mikado-themes pawfriends - Pet Shop And Veterinary Wordpress Theme
Wordpress
Wordpress wordpress

Fri, 20 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through <= 1.3.
Title WordPress PawFriends - Pet Shop and Veterinary WordPress theme theme <= 1.3 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References

Subscriptions

Mikado-themes Pawfriends - Pet Shop And Veterinary Wordpress Theme
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:53:30.297Z

Reserved: 2026-01-07T12:21:36.722Z

Link: CVE-2026-22383

cve-icon Vulnrichment

Updated: 2026-02-20T19:04:53.774Z

cve-icon NVD

Status : Deferred

Published: 2026-02-20T16:22:37.933

Modified: 2026-04-28T19:36:33.293

Link: CVE-2026-22383

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T17:45:16Z

Weaknesses