Executive brief
The Koji WordPress theme contains an access control flaw that allows unauthenticated attackers to view pages and perform actions they should not be permitted to access. This could enable attackers to view other users' private data, modify content, or compromise website functionality without requiring any credentials or user interaction.
Technical details
The vulnerability is a broken access control issue in the Koji WordPress theme versions 2.2.1 and earlier. It permits unauthenticated attackers to bypass authorization checks and access restricted pages or perform administrative actions. The flaw requires only network access to the affected WordPress installation; no authentication or special privileges are needed to exploit it. Attackers can access sensitive data or perform unintended actions. The vulnerability is patched in version 2.2.2 and later.
Affected products
- WordPress.org Koji 2.2.1 and earlier
Timeline
- 2026-08-20: disclosed
- 2026: patched: Patched in version 2.2.2