WordPress · Kirki · CVE-2026-18347
**Name of the Vulnerable Software and Affected Versions**
Kirki – Freeform Page Builder, Website Builder & Customizer versions prior to 6.1.2
**Description**
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with custom-level access or higher can read arbitrary user metadata and sensitive record fields, such as email addresses, assigned roles, registration dates, and `user meta` values, for any WordPress user, including administrators. This is achieved by providing a target user ID with a user-type context to the frontend collection endpoint via the `context` parameter.
**Recommendations**
Update the plugin to a version newer than 6.1.1.