WordPress · Kirki · CVE-2026-18335
**Name of the Vulnerable Software and Affected Versions**
Kirki – Freeform Page Builder, Website Builder & Customizer versions prior to 6.2.1
**Description**
The plugin is susceptible to Blind Server-Side Request Forgery (SSRF), a flaw that allows an attacker to induce the server-side application to make requests to an unintended location. Unauthenticated attackers can exploit this via the `kirki data` parameter to send web requests to arbitrary locations from the web application, potentially querying or modifying information from internal services.
**Recommendations**
Update the plugin to a version newer than 6.2.0.
As a temporary mitigation, restrict or sanitize the use of the `kirki data` parameter.