Impact
Kirki WordPress plugin versions prior to 6.3.0 allow a user who has been granted content‑level access to change the status of collaboration comments left by other users. The plugin performs no check that the user is permitted to act on the specific comment. Consequently, a user who is not able to view the page on which a comment was made can still modify that comment.
Affected Systems
WordPress sites that include the Kirki plugin in the version range 6.0.0 through 6.2.5 are affected. The problem is fixed in Kirki 6.3.0 and later. Sites that remain on earlier releases are vulnerable if they grant content‑level access to users who should not have the ability to alter collaboration comments.
Risk and Exploitability
The vulnerability is an authenticated IDOR. An attacker needs to have valid login credentials of a user who has content‑level access but does not necessarily have visibility of the page containing the comment. The CVSS score of 2.2 classifies it as low severity. The EPSS score is below 1 % and the issue is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. When exploited, the attacker could alter the state of existing collaboration comments.
OpenCVE Enrichment