Authorization Bypass in Kirki Page Builder Plugin for WordPress
CVE-2026-18347

4.3MEDIUM

What is CVE-2026-18347?

The Kirki Page Builder plugin for WordPress is susceptible to an authorization bypass, allowing authenticated attackers with custom-level access to exploit the vulnerability. This weakness stems from the inadequate verification of user authorization when performing specific actions. As a result, attackers can access sensitive information, including arbitrary user metadata and crucial user fields, such as email addresses, user roles, registration dates, and additional metadata, by manipulating requests to the frontend collection endpoint.

Affected Version(s)

Kirki – Freeform Page Builder, Website Builder & Customizer 0 <= 6.1.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Datist Pham
.