PT-2026-61525 · WordPress · Kirki
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Kirki WordPress plugin versions prior to 6.0.12
Description
An authorization bypass exists in a REST route that allows unauthenticated users to overwrite the content of existing comments. Additionally, attackers can create pre-approved comments using a spoofed identity, which enables them to bypass standard comment moderation processes.
Recommendations
Update Kirki WordPress plugin to version 6.0.12 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kirki