Description
Missing Authorization vulnerability in Mikado-Themes Wanderland wanderland allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wanderland: from n/a through <= 1.5.
Published: 2026-01-22
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass
Action: Apply patch
AI Analysis

Impact

The vulnerability is a missing authorization check in Mikado‑Themes’ Wanderland theme, allowing an attacker to exploit incorrectly configured access‑control security levels. The flaw can enable unrestricted access to theme administrative functions, potentially permitting unauthorized viewing, modification, or deletion of site content and configuration.

Affected Systems

The affected product is the Mikado‑Themes Wanderland WordPress theme. Versions from the initial release up through 1.5 are vulnerable; any installation of the theme in those versions is impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation likely requires HTTP requests to the WordPress site, where an attacker can manipulate requests to bypass normal permission checks; the attack vector is inferred rather than explicitly documented in the provided data.

Generated by OpenCVE AI on April 28, 2026 at 18:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mikado‑Themes Wanderland to a version newer than 1.5 to obtain the vendor‑provided fix.
  • Reconfigure WordPress user roles and capabilities to ensure that only authorized users have access to theme‑related administrative pages.
  • Audit the site for any residual permissions that grant unnecessary access and adjust them to enforce strict access control in line with the vendor’s guidance.

Generated by OpenCVE AI on April 28, 2026 at 18:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 28 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 27 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mikado-themes
Mikado-themes wanderland
Wordpress
Wordpress wordpress
Vendors & Products Mikado-themes
Mikado-themes wanderland
Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Mikado-Themes Wanderland wanderland allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wanderland: from n/a through <= 1.5.
Title WordPress Wanderland theme <= 1.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Mikado-themes Wanderland
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T17:15:52.793Z

Reserved: 2026-01-07T13:43:59.552Z

Link: CVE-2026-22458

cve-icon Vulnrichment

Updated: 2026-01-27T17:31:20.580Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:34.793

Modified: 2026-04-28T19:36:38.797

Link: CVE-2026-22458

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T18:15:37Z

Weaknesses