SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84221

MEDIUM · CVSS 6.8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Kirki WordPress plugin prior to version 6.3.0 is vulnerable due to inadequate escaping of user-supplied identifiers in SQL queries, which allows users with editor-level access or higher to execute arbitrary SQL commands. This vulnerability can lead to unauthorized access to sensitive database information, including user credentials. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential data breaches.

CVE
CVE-2026-84221
Severity
MEDIUM
CVSS
6.8
EPSS
0.23%
WordPress

Original NVD Description

The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.