Junglewise Threat Intelligence

CVE-2026-57727: Themeum Kirki missing authorization in access control

CVE-2026-57727 · Severity: high · CVSS 7.5 · Published 2026-07-13

Technologies: Themeum Kirki. Vendors: Themeum.

Executive brief

Themeum Kirki is a popular framework used by WordPress developers to create customization options for themes. A security flaw in this tool allows unauthorized individuals to bypass access controls due to incorrectly configured security levels. This could lead to the exposure of sensitive site configuration data or unauthorized access to administrative features, potentially compromising the website's integrity.

Technical details

A Broken Access Control vulnerability (CWE-862) exists in the Themeum Kirki framework for WordPress through version 6.0.13. The issue stems from missing authorization checks or incorrectly configured security levels within the plugin's functions. An unauthenticated remote attacker can exploit this flaw to perform actions that should be restricted to higher-privileged users. According to the advisory, no official patch was available at the time of publication, though mitigation rules have been suggested by third-party security providers.

Affected products

  • Themeum Kirki <= 6.0.13

Timeline

  • 2026-05-20: disclosed: Reported by Psalms Christopher Matovu (ByteOverride)
  • 2026-07-06: advisory: Initial advisory published by Patchstack
  • 2026-07-13: advisory: NVD publication date

References

Related threats