Impact
The vulnerability is a missing authorization flaw in the Themeum Kirki WordPress plugin up to version 6.0.13. An attacker who can reach the plugin’s administrative interfaces can alter settings or perform privileged actions without proper role checks, potentially modifying theme data, compromising site configuration, or enabling further exploitation.
Affected Systems
WordPress sites that have the Kirki plugin installed with version 6.0.13 or earlier, regardless of the WordPress core version. The plugin is distributed by the vendor Themeum. Any site that uses this plugin is potentially exposed.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity of this access control issue, but the EPSS score of less than 1 % suggests that the likelihood of public exploitation remains low. The vulnerability is not listed in the CISA KEV catalog, which reduces the urgency of immediate remediation compared to actively exploited threats, yet the high impact warrants prompt action. Exploitation would require the attacker to be able to reach the plugin checks.
OpenCVE Enrichment