Impact
An unauthenticated Insecure Direct Object Reference (IDOR) flaw exists in the WordPress Kirki plugin up to version 6.0.11. The lack of proper authorization checks allows an attacker to reference protected objects—such as theme settings—without authentication, potentially exposing sensitive configuration data.
Affected Systems
The Kirki plugin manufactured by Themeum, versions 6.0.11 and earlier, is affected. WordPress sites that have this plugin installed and have not applied the latest update are vulnerable to IDOR attacks performed through unauthenticated HTTP requests that manipulate the plugin’s parameters. Updating to version 6.0.12 or later eliminates the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of < 1 % shows the current likelihood of exploitation is low. The vulnerability is not listed in CISA’s KEV catalog, so no widespread exploitation campaigns are documented. Attackers can target any exposed WordPress installation with the to the plugin’s endpoints to exploit the IDOR.
OpenCVE Enrichment