SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18347

MEDIUM · CVSS 4.3 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-16 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Kirki plugin for WordPress is vulnerable to an authorization bypass, allowing authenticated attackers with custom-level access or higher to access sensitive user metadata, including email addresses and roles, for any WordPress user. This vulnerability poses a risk of data exposure, particularly for sites with multiple user roles. WordPress site administrators and developers using this plugin should prioritize patching to mitigate potential data breaches.

CVE
CVE-2026-18347
Severity
MEDIUM
CVSS
4.3
EPSS
0.30%
WordPress

Original NVD Description

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.1.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to read arbitrary user metadata and sensitive user record fields — including email address, assigned roles, registration date, and any user_meta values — belonging to any WordPress user including administrators, by supplying a target user ID with a user-type context to the frontend collection endpoint.