Impact
The Kirki plugin for WordPress suffers from improper validation of a specified quantity in input handling, allowing an attacker to exploit unprotected functionality and execute arbitrary code, potentially compromising the entire site. This flaw is reported as a vulnerability that can be leveraged because the plugin fails to enforce the appropriate Access Control Lists (ACLs) on sensitive operations. The impact is a full compromise of application confidentiality, integrity, and availability, leading to malicious code execution under the privileges of a user accessing constrained functions.
Affected Systems
The issue affects all installations of the Kirki plugin version 6.3.1 and earlier. Users running WordPress sites that have the Kirki configuration plugin installed, from version n/a through 6.3.1, are vulnerable. The plugin is provided by the vendor Themeum.
Risk and Exploitability
The CVSS score is 8.2, indicating a high severity. EPSS is not available, so the likelihood is unknown, but the absence from the KEV catalog suggests no known widespread exploitation yet. The most likely attack vector is a web‑based request to the plugin’s administrative endpoint, taking advantage of ACL misconfiguration to execute code. The vulnerability requires that the attacker can access or otherwise reach the vulnerable function, so risk is higher for authenticated users with elevated privileges, though the unconstrained ACL may expose it to lower‑privileged roles.
OpenCVE Enrichment