PT-2026-54939 · WordPress · Kirki
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kirki – Freeform Page Builder, Website Builder & Customizer versions prior to 6.0.12
Description
An issue exists that allows unauthenticated attackers to extract full builder metadata and rendered HTML of any
kirki symbol post, including unpublished drafts. This is achieved by supplying a sequential WordPress post ID to the get single symbol function.Recommendations
Update the plugin to version 6.0.12 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kirki