Kirki

WordPress plugin · kirki · WordPress.org ↗
1
Critical
3
High
13
Known total
0
Unfixed
Running Kirki on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
CRITICAL
CVSS 9.1
Kirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apis
CVE.org
>=0, <6.0.12 v6.0.12 CVE-2026-13147 Jul 20, 2026
HIGH
CVSS 7.5
Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding
CVE.org
>=6.2.1, <6.3.0 v6.3.0 CVE-2026-84219 Sep 6, 2026
HIGH
CVSS 7.5
Kirki < 6.0.13 - Unauthenticated PHP Object Injection
CVE.org
>=0, <6.0.13 v6.0.13 CVE-2026-12720 Jul 31, 2026
HIGH
CVSS 8.6
Kirki < 6.0.13 - Unauthenticated SQL Injection
CVE.org
>=0, <6.0.13 v6.0.13 CVE-2026-12721 Jul 31, 2026
MEDIUM
CVSS 6.8
Kirki 6.0.0 - 6.3.0 - Author+ Stored XSS via Unsanitized SVG Upload
CVE.org
>=6.0.0, <6.3.1 v6.3.1 CVE-2026-84223 Sep 20, 2026
MEDIUM
CVSS 5.3
Kirki 6.2.1 - 6.2.5 - Unauthenticated Non-Public Post Content Disclosure via 'kirki_data' Parameter
CVE.org
>=6.2.1, <6.3.0 v6.3.0 CVE-2026-84222 Sep 9, 2026
MEDIUM
CVSS 6.8
Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID
CVE.org
>=6.0.0, <6.3.0 v6.3.0 CVE-2026-84221 Sep 5, 2026
MEDIUM
CVSS 5.3
Kirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_apis
CVE.org
>=0, <6.0.14 v6.0.14 CVE-2026-77754 Aug 26, 2026
MEDIUM
CVSS 6.8
Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload
CVE.org
>=0, <6.2.3 v6.2.3 CVE-2026-74992 Aug 20, 2026
MEDIUM
CVSS 6.5
Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions
CVE.org
>=0, <6.2.1 v6.2.1 CVE-2026-16747 Aug 12, 2026
MEDIUM
CVSS 5.3
Kirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderation Bypass via Component Library
CVE.org
>=0, <6.0.12 v6.0.12 CVE-2026-12723 Jul 20, 2026
MEDIUM
CVSS 4.3
Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password
CVE.org
>=0, <6.0.12 v6.0.12 CVE-2026-12724 Jul 20, 2026
LOW
CVSS 2.2
Kirki 6.0.0 - 6.2.5 - Authenticated Collaboration Comment Status Modification via IDOR
CVE.org
>=6.0.0, <6.3.0 v6.3.0 CVE-2026-84225 Sep 5, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.