VYPR

Kirki

by WordPress

Source repositories

CVEs (34)

  • CVE-2026-65436MedJul 27, 2026
    risk 0.00cvss 6.8epss 0.01

    Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.

  • CVE-2026-13464MedJul 24, 2026
    risk 0.00cvss 5.3epss 0.00

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0.14 via the 'context' parameter due to missing validation on a user controlled key. This makes it…

  • CVE-2026-13147CriJul 20, 2026
    risk 0.00cvss 9.1epss 0.01

    The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).

  • CVE-2026-12724MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to…

  • CVE-2026-12723MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment…

  • CVE-2026-15457MedJul 17, 2026
    risk 0.00cvss 4.9epss 0.01

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and…

  • CVE-2026-57727HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.00

    Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13.

  • CVE-2026-57726CriJul 13, 2026
    risk 0.00cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12.

  • CVE-2026-57725HigJul 13, 2026
    risk 0.00cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11.

  • CVE-2026-57724CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

  • CVE-2026-57680MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.

  • CVE-2026-12472MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.01

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…

  • CVE-2026-12122MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.01

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.11 via the get_single_symbol. This makes it possible for unauthenticated attackers to extract the full…

  • CVE-2026-57627MedJun 26, 2026
    risk 0.00cvss 4.9epss 0.00

    Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.

Page 2 of 2