All vulnerabilities
CVE-2026-84224
Medium
Kirki < 6.3.2 – Editor+ Blind SSRF via Remote Template URL
| Vendor | Kirki |
|---|---|
| Product | Kirki – WordPress plugin |
| Affected versions | 6.3.2 |
| Weakness | CWE-918 |
| CVSS vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N |
| Status | Published |
The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL before fetching it. Users with Editor-level access or higher may cause the server to send requests to otherwise inaccessible internal services and infer which services are reachable from the responses.
Impact
Potential access to internal services through server-side requests and inference of service reachability. The published record does not establish arbitrary data extraction or remote code execution.
Related disclosures
Medium
Kirki Unauthenticated Non-Public Post Content Disclosure via 'kirki_data' Parameter
Low
Code Snippets < 3.10.0 – Admin+ Network-Scoped Snippet Activation and Deactivation via update_code_snippet
Low
The Events Calendar 6.15.16.1 – 6.17.4.1 – Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST Routes
Medium
Kirki 6.0.0 – 6.3.0 – Author+ Stored XSS via Unsanitized SVG Upload
View all