SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-84225

LOW · CVSS 2.2 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Kirki WordPress plugin prior to version 6.3.0 is vulnerable as it fails to properly verify user permissions for modifying collaboration comments, allowing unauthorized users with content-level access to alter comments made by others. This could lead to misinformation or manipulation of user feedback on pages that the unauthorized user cannot access. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential risks associated with this vulnerability.

CVE
CVE-2026-84225
Severity
LOW
CVSS
2.2
EPSS
0.15%
WordPress

Original NVD Description

The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.