Impact
Kirki, a WordPress plugin, fails to sanitize the email subject and body supplied to the password‑reset routine before embedding them in an HTML message. This flaw allows an unauthenticated user to inject arbitrary HTML into the email that is delivered to a valid account holder, enabling phishing or delivery of malicious content. The weakness corresponds to CWE‑345.
Affected Systems
The vulnerability affects all deployments of the Kirki plugin running any version earlier than 6.0.12 on WordPress sites. The vendor is not explicitly identified in the CNA data, but impacts should be assessed for any site that has the plugin installed and not yet updated.
Risk and Exploitability
With a CVSS score of 4.3 the risk is moderate; the EPSS score of less than 1% indicates a low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack vector is unauthenticated and relies on access to the kirki‑forgot‑password endpoint, which is typically publicly reachable on the site. If exploited, the attacker can deliver deceptive emails that appear to originate from the legitimate site and may lead to credential compromise or other social‑engineering attacks.
OpenCVE Enrichment