Impact
The Mikado-Themes Roam theme contains an Authorization Bypass Through User‑Controlled Key vulnerability, also known as IDOR, allowing an attacker to request resources that they are not authorized to access. This flaw stems from incorrectly configured access control security levels. If exploited, an attacker could read or modify protected content, leading to confidentiality or integrity violations.
Affected Systems
Affected systems are WordPress sites using the Mikado-Themes Roam theme through version 2.1.1. The issue applies to any installation that has not yet upgraded beyond this release.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate impact. The EPSS score shows a less than 1% likelihood of exploitation, suggesting a low probability under current threat conditions. The vulnerability is not listed in CISA’s KEV catalog. Attacks would likely exploit direct URL manipulation to access privileged objects; this inference is drawn from the description of an IDOR flaw and the nature of the weakness (CWE‑639).
OpenCVE Enrichment