Impact
The Kirki WordPress plugin allows the server to fetch a URL supplied by a user without validation. An unauthenticated attacker can thereby force the site to make HTTP requests to arbitrary hosts, potentially exposing internal resources or facilitating further attacks.
Affected Systems
The weakness impacts the Kirki plugin for WordPress on all versions older than 6.0.12. The vendor is listed only as Kirki.
Risk and Exploitability
The CVSS score of 9.1 marks this as high severity, while an EPSS score of less than 1% indicates a currently low probability of exploitation. It is not listed in the CISA KEV catalog. Based on the description, the likely attack path is via the unauthenticated kirki_get_apis endpoint, which accepts a URL parameter and initiates a server‑side request without validation.
OpenCVE Enrichment