CVE-2026-22403 | Mikado-Themes Innovio Plugin up to 1.7 on WordPress filename control
A vulnerability marked as critical has been reported in Mikado-Themes Innovio Plugin up to 1.7 on WordPress. Affected is an unknown function. This manipulation causes improper control of filename for include/require statement in php program ('php remote file inclusion').
The identification of this vulnerability is CVE-2026-22403. It is possible to initiate the attack remotely. There is no exploit available.