All vulnerabilities
CVE-2026-84222
Medium
CVSS 5.3
Kirki Unauthenticated Non-Public Post Content Disclosure via 'kirki_data' Parameter
| Vendor | Kirki |
|---|---|
| Product | Kirki |
| Affected versions | 6.2.1 - 6.2.5 |
| Weakness | CWE-200 |
| CVSS vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| Reported | 2026-08-10 |
| Disclosed | 2026-09-07 |
| Status | Published |
Kirki versions 6.2.1 through 6.2.5 do not verify whether a requester is authorized to view a post before rendering its content via the kirki_data parameter. This allows unauthenticated attackers to disclose the content of non-public posts and pages, including private, draft, pending, and trashed content. The issue is fixed in version 6.3.0.
Impact
Sensitive or unpublished content (drafts, private pages, internal notes stored as posts) can be exposed to any unauthenticated visitor, potentially leaking business-critical or embargoed information before intended publication.