Impact
The Kirki WordPress plugin (before version 6.3.2) fails to validate the host of a supplied URL before fetching it. An attacker with editor rights or higher can supply an arbitrary internal address, causing the site’s server to make HTTP requests to that address. Because the plugin exposes the response status, the attacker can determine whether an internal service is reachable, effectively performing blind SSRF. This can reveal internal network structure and provide information that might aid further attacks, though the flaw itself does not directly enable code execution.
Affected Systems
WordPress installations that use the Kirki plugin with a version earlier than 6.3.2. Users with editor or higher privileges are able to supply the malicious URL.
Risk and Exploitability
The CVSS score of 4.1 indicates moderate severity, and the EPSS score is not available, so it is unclear how frequently it is exploited. The vulnerability is not listed in CISA KEV. Attackers require only common editor permissions and the plugin’s ability to accept URL input; no additional network access is needed beyond the web server. The flaw alone does not grant code execution; it solely enables the site to make internal calls and reveal which internal addresses are reachable from the response.
OpenCVE Enrichment