Description
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 6.2.0 via the 'kirki_data' Parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Published: 2026-09-24
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server-Side Request Forgery
Action: Patch Now
AI Analysis

Impact

The vulnerability in the Kirki – Freeform Page Builder, Website Builder & Customizer plugin allows an unauthenticated user to supply a value to the 'kirki_data' parameter that is sent directly by the server to a remote location, enabling a blind Server‑Side Request Forgery (SSRF). This can be used to query internal network services or to modify information on them, thereby compromising confidentiality and potentially integrity of sensitive data. The weakness is identified as CWE‑918.

Affected Systems

The affected product is the Kirki – Freeform Page Builder, Website Builder & Customizer plugin by Themeum, any version up to and including 6.2.0.

Risk and Exploitability

With a CVSS score of 5.4 the vulnerability is considered moderate. No EPSS data is provided and the issue is not listed in the CISA KEV catalog, indicating that the public exploitation risk is currently not high. The attack vector is based on unauthenticated web requests, requiring only that the attacker can reach the WordPress site. If the plugin is accessible, an attacker can target internal resources that are otherwise not exposed to the Internet.

Generated by OpenCVE AI on September 24, 2026 at 10:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Kirki plugin to a version newer than 6.2.0 that removes the dangerous parameter handling.
  • If an immediate update is not feasible, disable or uninstall the Kirki plugin to eliminate the SSRF surface.
  • Configure the server or a web application firewall to block outbound requests originating from the WordPress application that are not explicitly whitelisted.
  • Verify that no unintended internal services are accessible via the WordPress site after remediation.

Generated by OpenCVE AI on September 24, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Themeum
Themeum kirki – Freeform Page Builder, Website Builder & Customizer
Wordpress
Wordpress wordpress
Vendors & Products Themeum
Themeum kirki – Freeform Page Builder, Website Builder & Customizer
Wordpress
Wordpress wordpress

Thu, 24 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 6.2.0 via the 'kirki_data' Parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Title Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Unauthenticated Blind Server-Side Request Forgery via 'kirki_data' Parameter
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Themeum Kirki – Freeform Page Builder, Website Builder & Customizer
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-24T15:04:06.565Z

Reserved: 2026-07-29T20:52:50.109Z

Link: CVE-2026-18335

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-24T10:17:37.637

Modified: 2026-09-24T16:17:07.287

Link: CVE-2026-18335

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T10:30:18Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)