Impact
The Kirki WordPress plugin before version 6.3.0 contains a SQL injection flaw because it does not escape a user‑supplied identifier before incorporating it into a database query. This flaw allows users with the Editor role or higher to inject arbitrary SQL, enabling them to read the entire database, including credential information. The weakness is a classic CWE‑89 SQL Injection vulnerability.
Affected Systems
WordPress sites that have the Kirki plugin installed in any of the vulnerable releases from 6.0.0 through 6.2.5 are affected. The plugin must be present and actively used on an administrator’s site.
Risk and Exploitability
The exploitation requires that the attacker already possess Editor or higher privileges within the WordPress admin interface, which limits the attack surface but still poses a significant risk for sites with compromised credentials. While the EPSS score is not available and the vulnerability is not listed in CISA KEV, the high severity of SQL injection combined with the potential to exfiltrate passwords means the risk is non‑negligible for impacted installations.
OpenCVE Enrichment