PT-2026-61532 · WordPress · Kirki
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Kirki WordPress plugin versions prior to 6.0.12
Description
An issue exists where the software fails to validate a user-supplied URL before requesting it server-side. This allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF), a technique where the server is coerced into making HTTP requests to arbitrary hosts.
Recommendations
Update Kirki WordPress plugin to version 6.0.12 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kirki