All vulnerabilities
CVE-2026-84222 Medium CVSS 5.3

Kirki Unauthenticated Non-Public Post Content Disclosure via 'kirki_data' Parameter

Vendor Kirki
Product Kirki
Affected versions 6.2.1 - 6.2.5
Weakness CWE-200
CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reported 2026-08-10
Disclosed 2026-09-07
Status Published
Kirki versions 6.2.1 through 6.2.5 do not verify whether a requester is authorized to view a post before rendering its content via the kirki_data parameter. This allows unauthenticated attackers to disclose the content of non-public posts and pages, including private, draft, pending, and trashed content. The issue is fixed in version 6.3.0.

Impact

Sensitive or unpublished content (drafts, private pages, internal notes stored as posts) can be exposed to any unauthenticated visitor, potentially leaking business-critical or embargoed information before intended publication.