CVE-2026-24631 PUBLISHED

WordPress Rosebud theme <= 1.4 - Insecure Direct Object References (IDOR) vulnerability

Assigner: Patchstack
Reserved: 23.01.2026 Published: 23.01.2026 Updated: 23.01.2026

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Rosebud rosebud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rosebud: from n/a through <= 1.4.

Product Status

Vendor Mikado-Themes
Product Rosebud
Versions Default: unaffected
  • affected from n/a to <= 1.4 (incl.)

Credits

  • Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program finder

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE

Impacts

  • Exploiting Incorrectly Configured Access Control Security Levels