Impact
The Kirki WordPress plugin contains a Missing Authorization flaw in its get_single_symbol AJAX endpoint. Unauthenticated callers can submit a numeric WordPress post ID and retrieve the full builder metadata and rendered HTML of any kirki_symbol post, including unpublished drafts. This allows sensitive information that should be protected, such as page structure and unpublished content, to be exposed to any visitor. The weakness is CWE‑862.
Affected Systems
The vulnerability affects the Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress, versions up to and including 6.0.11. Any WordPress site running those versions is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low current likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the publicly accessible AJAX endpoint by supplying valid post identifiers, gaining unauthorized access to confidential page data without authentication.
OpenCVE Enrichment