Description
The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response.
Published: 2026-10-09
Score: 4.1 Medium
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

The Kirki WordPress plugin (before version 6.3.2) fails to validate the host of a supplied URL before fetching it. An attacker with editor rights or higher can supply an arbitrary internal address, causing the site’s server to make HTTP requests to that address. Because the plugin exposes the response status, the attacker can determine whether an internal service is reachable, effectively performing blind SSRF. This can reveal internal network structure and provide information that might aid further attacks, though the flaw itself does not directly enable code execution.

Affected Systems

WordPress installations that use the Kirki plugin with a version earlier than 6.3.2. Users with editor or higher privileges are able to supply the malicious URL.

Risk and Exploitability

The CVSS score of 4.1 indicates moderate severity, and the EPSS score is not available, so it is unclear how frequently it is exploited. The vulnerability is not listed in CISA KEV. Attackers require only common editor permissions and the plugin’s ability to accept URL input; no additional network access is needed beyond the web server. The flaw alone does not grant code execution; it solely enables the site to make internal calls and reveal which internal addresses are reachable from the response.

Generated by OpenCVE AI on October 9, 2026 at 10:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Kirki to version 6.3.2 or later to remove the SSRF flaw.
  • If an update is not possible, limit editor and higher privileges from creating or editing content that triggers the plugin’s URL fetching.
  • Block outbound requests from the web server to internal networks using firewall rules or host‑table restrictions.
  • Monitor HTTP logs for unexpected internal requests and investigate anomalies.

Generated by OpenCVE AI on October 9, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Fri, 09 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response.
Title Kirki < 6.3.2 - Editor+ Blind SSRF via Remote Template URL
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-09T08:08:06.041Z

Reserved: 2026-09-01T11:50:34.724Z

Link: CVE-2026-84224

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T09:17:10.000

Modified: 2026-10-09T09:17:10.000

Link: CVE-2026-84224

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T10:30:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)