Impact
The Kirki WordPress plugin versions 6.2.1 through 6.2.5 lack an authorization check before rendering a post’s content when the 'kirki_data' parameter is used. As a result, any visitor, even without logging in, can request and receive the full text of private, draft, pending, or trashed posts. This flaw provides a straightforward read‑only bypass of the site's access control and can expose confidential or sensitive information that site administrators intend to keep hidden from unauthenticated viewers.
Affected Systems
WordPress sites that have the Kirki plugin installed at versions 6.2.1, 6.2.2, 6.2.3, 6.2.4, or 6.2.5 are affected. Upgrading to any 6.3.0 or later release removes the flaw.
Risk and Exploitability
The vulnerability enables unauthenticated users to obtain private content; the CVSS score is 5.3 and the EPSS value is < 1%. It is not in the CISA KEV catalog. Given the lack of authentication or advanced prerequisites, the flaw is trivial to exploit and could allow widespread information leakage if a site’s content is confidential. No denial‑of‑service impact is described and no protected resources beyond content are impacted.
OpenCVE Enrichment