PT-2026-64227 · WordPress · Kirki

·

CVE-2026-13464

·

Published

2026-07-24

·

Updated

2026-07-24

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kirki versions prior to 6.0.15
Description The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress contains an Insecure Direct Object Reference (IDOR) flaw. This occurs due to missing validation on a user-controlled key within the context parameter. Unauthenticated attackers can exploit this by providing an arbitrary post ID via the context parameter and an attacker-controlled block template to read the full title, content, and excerpt of any WordPress post, including drafts, pending, privately published, password-protected, and trashed posts, regardless of the author.
Recommendations Update the plugin to a version newer than 6.0.14. As a temporary mitigation, restrict or filter the use of the context parameter to prevent unauthorized access to post data.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13464

Affected Products

Kirki