Description
The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.
Published: 2026-09-05
Score: 2.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of collaboration comments by users with content-level access
Action: Apply Update
AI Analysis

Impact

Kirki WordPress plugin versions prior to 6.3.0 allow a user who has been granted content‑level access to change the status of collaboration comments left by other users. The plugin performs no check that the user is permitted to act on the specific comment. Consequently, a user who is not able to view the page on which a comment was made can still modify that comment.

Affected Systems

WordPress sites that include the Kirki plugin in the version range 6.0.0 through 6.2.5 are affected. The problem is fixed in Kirki 6.3.0 and later. Sites that remain on earlier releases are vulnerable if they grant content‑level access to users who should not have the ability to alter collaboration comments.

Risk and Exploitability

The vulnerability is an authenticated IDOR. An attacker needs to have valid login credentials of a user who has content‑level access but does not necessarily have visibility of the page containing the comment. The CVSS score of 2.2 classifies it as low severity. The EPSS score is below 1 % and the issue is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. When exploited, the attacker could alter the state of existing collaboration comments.

Generated by OpenCVE AI on September 6, 2026 at 13:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Kirki plugin to version 6.3.0 or later.
  • Restrict content‑level access to only trusted users who need it to edit collaboration comments.
  • Review WordPress user roles and remove unnecessary collaboration permissions from users who should not modify comments.

Generated by OpenCVE AI on September 6, 2026 at 13:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 06 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 05 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Kirki
Kirki kirki
Wordpress
Wordpress wordpress
Weaknesses CWE-639
Vendors & Products Kirki
Kirki kirki
Wordpress
Wordpress wordpress

Sat, 05 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.
Title Kirki 6.0.0 - 6.2.5 - Authenticated Collaboration Comment Status Modification via IDOR
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-06T10:37:38.481Z

Reserved: 2026-09-01T11:50:36.164Z

Link: CVE-2026-84225

cve-icon Vulnrichment

Updated: 2026-09-06T10:28:02.772Z

cve-icon NVD

Status : Deferred

Published: 2026-09-05T07:17:13.760

Modified: 2026-09-08T19:09:21.310

Link: CVE-2026-84225

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-06T13:15:06Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key