Junglewise Threat Intelligence

CVE-2026-13464: Themeum Kirki Page Builder IDOR in context parameter

CVE-2026-13464 · Severity: medium · CVSS 5.3 · Published 2026-07-24

Vendors: Themeum.

Executive brief

A vulnerability in the Kirki page builder plugin for WordPress allows unauthorized individuals to view private website content. This includes drafts, password-protected posts, and deleted items that are not intended for public viewing. An attacker can exploit this to access sensitive information or internal communications stored within the website's database.

Technical details

The Kirki plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) flaw due to missing validation on the 'context' parameter within its REST API controllers. Specifically, the vulnerability exists in the CollectionController and FrontendRESTController components. An unauthenticated attacker can supply an arbitrary post ID via the 'context' parameter alongside an attacker-controlled block template to bypass authorization checks. This allows the attacker to retrieve the full title, content, and excerpt of any post, including those in draft, pending, private, password-protected, or trashed states. The issue is addressed in versions following 6.0.14.

Affected products

  • Themeum Kirki – Freeform Page Builder, Website Builder & Customizer up to, and including, 6.0.14

Timeline

  • 2026-07-24: disclosed: Initial publication of the CVE record
  • 2026-07-24: advisory: Wordfence published detailed advisory

References