Remote Code Execution in Kirki WordPress Plugin Affecting Site Security
CVE-2026-84224
Key Information:
Badges
What is CVE-2026-84224?
The Kirki WordPress plugin prior to version 6.3.2 contains a flaw that fails to properly validate the host of a provided URL before making a fetch request. This oversight allows users with at least editor-level permissions to send requests to internal services that should ideally be unreachable from the web. Additionally, attackers may exploit this vulnerability to ascertain the status of these internal services based on the responses received, potentially leading to further attacks and data exposure.
Affected Version(s)
Kirki 0 < 6.3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved