Impact
The vulnerability resides in the Kirki WordPress plugin prior to version 6.0.12, where a REST endpoint performs no authorization checks. This deficiency allows any user to craft requests that overwrite existing comment content or insert new comments that are automatically approved, thereby circumventing the site’s moderation controls. The effect is the unauthorized alteration or injection of user‑generated content, which can be used to defame, spread spam, or inject malicious links.
Affected Systems
Systems running the Kirki WordPress plugin before version 6.0.12 are affected. All installations of Kirki with older versions should be examined for the vulnerability.
Risk and Exploitability
Based on the lack of an authorization check on its REST endpoint, the likely attack vector involves unauthenticated HTTP requests to that route, allowing remote attackers to modify or insert comments without elevated privileges. The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would compromise the integrity of user discussions and potentially spread defamation or spam.
OpenCVE Enrichment