Unrated severityNVD Advisory· Published Sep 5, 2026
Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID
CVE-2026-84221
Description
The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/6c34da62-46fb-4dd4-a433-bd3df4d9fcfd/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.