Description
The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.
Published: 2026-09-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a user granted content-level access to change the status of collaboration comments left by other users, even on pages they cannot view. This lack of authorization checks permits malicious users to alter comment states, potentially defacing collaborative content and misleading stakeholders. The flaw directly impacts confidentiality, integrity, and public trust in collaborative discussions within the project.

Affected Systems

WordPress installations that use the Kirki plugin version 6.0.0 through 6.2.5 are affected. The issue is resolved in Kirki version 6.3.0 and later. Sites running older versions may allow any user with content-level access to modify comments on pages they cannot open.

Risk and Exploitability

The attack vector is authenticated IDOR; an attacker must possess valid login credentials with content-level permissions. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited but still significant exploitation risk. If exploited, an attacker could change the state of collaboration comments across the site, undermining the reliability of project feedback channels.

Generated by OpenCVE AI on September 5, 2026 at 07:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Kirki plugin to version 6.3.0 or later.
  • Restrict content‑level access only to trusted administrators and review user capabilities.
  • Audit WordPress user roles and adjust permissions to remove unnecessary collaboration privileges.

Generated by OpenCVE AI on September 5, 2026 at 07:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Kirki
Kirki kirki
Wordpress
Wordpress wordpress
Weaknesses CWE-639
Vendors & Products Kirki
Kirki kirki
Wordpress
Wordpress wordpress

Sat, 05 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.
Title Kirki 6.0.0 - 6.2.5 - Authenticated Collaboration Comment Status Modification via IDOR
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-05T06:00:08.348Z

Reserved: 2026-09-01T11:50:36.164Z

Link: CVE-2026-84225

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-05T07:17:13.760

Modified: 2026-09-05T07:17:13.760

Link: CVE-2026-84225

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T07:45:05Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key