Description
The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticated users to run any shortcode registered on the site, which on a default install leads to disclosure of the site administrator's email address and an arbitrary-recipient mail relay from the victim's domain.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 12 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticated users to run any shortcode registered on the site, which on a default install leads to disclosure of the site administrator's email address and an arbitrary-recipient mail relay from the victim's domain. | |
| Title | Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-12T12:12:18.556Z
Reserved: 2026-07-23T12:09:27.936Z
Link: CVE-2026-16747
No data.
Status : Received
Published: 2026-08-12T12:17:47.053
Modified: 2026-08-12T12:17:47.053
Link: CVE-2026-16747
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.