Insecure Direct Object Reference in Kirki Page Builder Plugin for WordPress
CVE-2026-13464

5.3MEDIUM

What is CVE-2026-13464?

The Kirki Page Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference, allowing unauthorized users to access the content of any WordPress post. This vulnerability stems from insufficient validation on the 'context' parameter, enabling attackers to supply arbitrary post IDs. As a result, they can read titles, contents, and excerpts of posts that should remain private, such as drafts, pending, and password-protected posts. This risk is present in all versions up to and including 6.0.14, impacting the security and integrity of user content.

Affected Version(s)

Kirki – Freeform Page Builder, Website Builder & Customizer 0 <= 6.0.14

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abu Hurayra (HurayraIIT)
.