Kirki
by WordPress
Source repositories
CVEs (34)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65436 | Med | 0.00 | 6.8 | 0.01 | Jul 27, 2026 | Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions. | ||
| CVE-2026-13464 | Med | 0.00 | 5.3 | 0.00 | Jul 24, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0.14 via the 'context' parameter due to missing validation on a user controlled key. This makes it… | ||
| CVE-2026-13147 | Cri | 0.00 | 9.1 | 0.01 | Jul 20, 2026 | The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery). | ||
| CVE-2026-12724 | Med | 0.00 | 4.3 | 0.00 | Jul 20, 2026 | The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to… | ||
| CVE-2026-12723 | Med | 0.00 | 5.3 | 0.00 | Jul 20, 2026 | The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment… | ||
| CVE-2026-15457 | Med | 0.00 | 4.9 | 0.01 | Jul 17, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and… | ||
| CVE-2026-57727 | Hig | 0.00 | 7.5 | 0.00 | Jul 13, 2026 | Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13. | ||
| CVE-2026-57726 | Cri | 0.00 | 9.3 | 0.00 | Jul 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12. | ||
| CVE-2026-57725 | Hig | 0.00 | 7.1 | 0.00 | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11. | ||
| CVE-2026-57724 | Cri | 0.00 | 9.8 | 0.01 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12. | ||
| CVE-2026-57680 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions. | ||
| CVE-2026-12472 | Med | 0.00 | 5.3 | 0.01 | Jul 2, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes… | ||
| CVE-2026-12122 | Med | 0.00 | 5.3 | 0.01 | Jul 2, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.11 via the get_single_symbol. This makes it possible for unauthenticated attackers to extract the full… | ||
| CVE-2026-57627 | Med | 0.00 | 4.9 | 0.00 | Jun 26, 2026 | Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions. |
- risk 0.00cvss 6.8epss 0.01
Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.
- risk 0.00cvss 5.3epss 0.00
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0.14 via the 'context' parameter due to missing validation on a user controlled key. This makes it…
- risk 0.00cvss 9.1epss 0.01
The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).
- risk 0.00cvss 4.3epss 0.00
The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to…
- risk 0.00cvss 5.3epss 0.00
The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment…
- risk 0.00cvss 4.9epss 0.01
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and…
- risk 0.00cvss 7.5epss 0.00
Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13.
- risk 0.00cvss 9.3epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12.
- risk 0.00cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11.
- risk 0.00cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.
- risk 0.00cvss 5.3epss 0.01
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…
- risk 0.00cvss 5.3epss 0.01
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.11 via the get_single_symbol. This makes it possible for unauthenticated attackers to extract the full…
- risk 0.00cvss 4.9epss 0.00
Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.
Page 2 of 2