Impact
An unauthenticated Insecure Direct Object Reference vulnerability exists in the WordPress Kirki plugin through version 6.0.11. The flaw permits attackers to reference protected objects such as theme settings without performing any authentication, thereby enabling a direct authorization bypass that can expose or alter sensitive configuration data.
Affected Systems
WordPress sites running the Kirki plugin from Themeum in version 6.0.11 or earlier are affected. Installing the latest version 6.0.12 or later removes the vulnerability.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector involves sending crafted HTTP requests to the plugin’s endpoints to reference theme settings without authentication. The CVSS score of 6.5 denotes moderate severity, while an EPSS score of < 1 % suggests a low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog, indicating no widely reported attacks. Exploitation requires only standard HTTP requests that manipulate the plugin’s parameters, with no authentication required.
OpenCVE Enrichment