Description
The Kirki WordPress plugin before 6.3.0 does not check whether the requester is allowed to read a post before rendering and returning its page content, allowing unauthenticated users to retrieve the content of pages that are not publicly available, such as private, draft, pending and trashed ones.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: unauthorized disclosure of non-public post content
Action: Apply Patch
AI Analysis

Impact

The Kirki WordPress plugin versions 6.2.1 through 6.2.5 lack an authorization check before rendering a post’s content when the 'kirki_data' parameter is used. As a result, any visitor, even without logging in, can request and receive the full text of private, draft, pending, or trashed posts. This flaw provides a straightforward read‑only bypass of the site's access control and can expose confidential or sensitive information that site administrators intend to keep hidden from unauthenticated viewers.

Affected Systems

WordPress sites that have the Kirki plugin installed at versions 6.2.1, 6.2.2, 6.2.3, 6.2.4, or 6.2.5 are affected. Upgrading to any 6.3.0 or later release removes the flaw.

Risk and Exploitability

The vulnerability enables unauthenticated users to obtain private content; the CVSS score is 5.3 and the EPSS value is < 1%. It is not in the CISA KEV catalog. Given the lack of authentication or advanced prerequisites, the flaw is trivial to exploit and could allow widespread information leakage if a site’s content is confidential. No denial‑of‑service impact is described and no protected resources beyond content are impacted.

Generated by OpenCVE AI on September 9, 2026 at 18:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Kirki plugin to version 6.3.0 or later
  • If a patch is not immediately available, disable the Kirki plugin to prevent unauthenticated requests
  • Apply access restrictions to the kirki endpoint (e.g., via server rules or plugin settings) to limit request scope

Generated by OpenCVE AI on September 9, 2026 at 18:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Kirki
Kirki kirki
Wordpress
Wordpress wordpress
Vendors & Products Kirki
Kirki kirki
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Kirki WordPress plugin before 6.3.0 does not check whether the requester is allowed to read a post before rendering and returning its page content, allowing unauthenticated users to retrieve the content of pages that are not publicly available, such as private, draft, pending and trashed ones.
Title Kirki 6.2.1 - 6.2.5 - Unauthenticated Non-Public Post Content Disclosure via 'kirki_data' Parameter
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-09T15:29:32.155Z

Reserved: 2026-09-01T11:50:25.666Z

Link: CVE-2026-84222

cve-icon Vulnrichment

Updated: 2026-09-09T15:28:14.428Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:18.047

Modified: 2026-09-09T16:17:12.843

Link: CVE-2026-84222

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-285

    Improper Authorization