Blind Server-Side Request Forgery in Kirki Page Builder Plugin by WordPress
CVE-2026-18335
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 September 2026
What is CVE-2026-18335?
The Kirki β Freeform Page Builder, Website Builder & Customizer plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit a blind server-side request forgery via the 'kirki_data' parameter. This enables the potential for attackers to execute web requests to arbitrary locations, which could facilitate the querying and modification of sensitive information from internal services.
Affected Version(s)
Kirki β Freeform Page Builder, Website Builder & Customizer 0 <= 6.2.0