Impact
The vulnerability allows a user granted content-level access to change the status of collaboration comments left by other users, even on pages they cannot view. This lack of authorization checks permits malicious users to alter comment states, potentially defacing collaborative content and misleading stakeholders. The flaw directly impacts confidentiality, integrity, and public trust in collaborative discussions within the project.
Affected Systems
WordPress installations that use the Kirki plugin version 6.0.0 through 6.2.5 are affected. The issue is resolved in Kirki version 6.3.0 and later. Sites running older versions may allow any user with content-level access to modify comments on pages they cannot open.
Risk and Exploitability
The attack vector is authenticated IDOR; an attacker must possess valid login credentials with content-level permissions. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited but still significant exploitation risk. If exploited, an attacker could change the state of collaboration comments across the site, undermining the reliability of project feedback channels.
OpenCVE Enrichment