CyberRota Analysis
AI-GeneratedThe Kirki WordPress plugin prior to version 6.3.0 is vulnerable as it fails to properly verify user permissions for modifying collaboration comments, allowing unauthorized users with content-level access to alter comments made by others. This could lead to misinformation or manipulation of user feedback on pages that the unauthorized user cannot access. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential risks associated with this vulnerability.
Original NVD Description
The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.