Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Datist Pham

#54431of 56,330
4.3Total CVSS
Vulnerabilities · 1
PT-2026-73135
4.3
2026-08-16
WordPress · Kirki · CVE-2026-18347
**Name of the Vulnerable Software and Affected Versions** Kirki – Freeform Page Builder, Website Builder & Customizer versions prior to 6.1.2 **Description** An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with custom-level access or higher can read arbitrary user metadata and sensitive record fields, such as email addresses, assigned roles, registration dates, and `user meta` values, for any WordPress user, including administrators. This is achieved by providing a target user ID with a user-type context to the frontend collection endpoint via the `context` parameter. **Recommendations** Update the plugin to a version newer than 6.1.1.