Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-77754 | 2 Kirki, Wordpress | 2 Kirki, Wordpress | 2026-08-26 | 5.3 Medium |
| The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJAX actions, allowing unauthenticated users to retrieve the email addresses of registered users and comment authors, as well as non-public page content and settings. | ||||
| CVE-2026-74992 | 2 Kirki, Wordpress | 2 Kirki, Wordpress | 2026-08-20 | 6.8 Medium |
| The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all unwanted files after extracting them, allowing such users to upload arbitrary files to a web accessible directory, leading to Stored XSS as well as RCE on some server configurations. | ||||
| CVE-2026-16747 | 2 Kirki, Wordpress | 2 Kirki, Wordpress | 2026-08-12 | 6.5 Medium |
| The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticated users to run any shortcode registered on the site, which on a default install leads to disclosure of the site administrator's email address and an arbitrary-recipient mail relay from the victim's domain. | ||||
| CVE-2026-13147 | 2 Kirki, Wordpress | 2 Kirki, Wordpress | 2026-08-04 | 9.1 Critical |
| The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery). | ||||
Page 1 of 1.