Impact
The Kirki WordPress plugin, versions earlier than 6.0.14, has a public AJAX action named 'kirki_get_apis' that fails to perform a capability check. This flaw allows unauthenticated users to retrieve the email addresses of all registered users and comment authors, as well as non‑public page content and settings. The result is a disclosure of personally identifiable information and internal configuration details, classified as CWE‑200.
Affected Systems
All installations of the Kirki plugin for WordPress running any version older than 6.0.14 are affected. The vendor appears as Unknown: Kirki in CNA records, indicating no assigned organizational owner in the official registry.
Risk and Exploitability
The vulnerability is exploitable through a simple HTTP request to the AJAX endpoint; no authentication or special privileges are required. The EPSS score is less than 1 %, implying a low probability of exploitation, but the ease of the attack path and the sensitivity of the exposed data mean the potential impact remains significant. The CVSS score of 5.3 indicates moderate severity. Attackers can use the exposed emails for phishing, enumeration, or other social engineering attacks. The issue is not listed in CISA KEV.
OpenCVE Enrichment