GHSA-78r9-6m52-hhpvMediumCVSS 6.8

The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using...

Published
September 5, 2026
Last Modified
September 6, 2026

🔗 CVE IDs covered (1)

📋 Description

The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.

🔗 References (3)