Impact
The vulnerability in the Kirki – Freeform Page Builder, Website Builder & Customizer plugin allows an unauthenticated user to supply a value to the 'kirki_data' parameter that is sent directly by the server to a remote location, enabling a blind Server‑Side Request Forgery (SSRF). This can be used to query internal network services or to modify information on them, thereby compromising confidentiality and potentially integrity of sensitive data. The weakness is identified as CWE‑918.
Affected Systems
The affected product is the Kirki – Freeform Page Builder, Website Builder & Customizer plugin by Themeum, any version up to and including 6.2.0.
Risk and Exploitability
With a CVSS score of 5.4 the vulnerability is considered moderate. No EPSS data is provided and the issue is not listed in the CISA KEV catalog, indicating that the public exploitation risk is currently not high. The attack vector is based on unauthenticated web requests, requiring only that the attacker can reach the WordPress site. If the plugin is accessible, an attacker can target internal resources that are otherwise not exposed to the Internet.
OpenCVE Enrichment