Impact
The Kirki WordPress plugin, versions earlier than 6.0.14, contains a public AJAX action named 'kirki_get_apis' that omits a capability check. This flaw enables unauthenticated users to retrieve email addresses of all registered users and comment authors, together with non‑public page content and settings. The vulnerability results in an information disclosure that can expose personally identifiable data and internal configuration details (CWE‑200).
Affected Systems
All installations of the Kirki plugin for WordPress running any version older than 6.0.14 are affected. The vendor identified as Unknown: Kirki indicates that the product is not tied to a specific organization in the CNA records.
Risk and Exploitability
The flaw is exploitable via a simple HTTP request to the AJAX endpoint; no authentication or special privileges are required. Although EPSS data is unavailable, the presence of the public endpoint means the potential for abuse is high. The vulnerability is not listed in CISA KEV, but the impact of exposing user emails makes it a high‑severity information disclosure. Attackers can use the exposed emails for phishing or to enumerate active users on the site.
OpenCVE Enrichment