All vulnerabilities
CVE-2026-84224 Medium

Kirki < 6.3.2 – Editor+ Blind SSRF via Remote Template URL

Vendor Kirki
Product Kirki – WordPress plugin
Affected versions 6.3.2
Weakness CWE-918
CVSS vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Status Published
The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL before fetching it. Users with Editor-level access or higher may cause the server to send requests to otherwise inaccessible internal services and infer which services are reachable from the responses.

Impact

Potential access to internal services through server-side requests and inference of service reachability. The published record does not establish arbitrary data extraction or remote code execution.

Related disclosures

View all