Junglewise Threat Intelligence

CVE-2026-84222: Kirki plugin unauthenticated non-public post content disclosure

CVE-2026-84222 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Vendors: Kirki.

Executive brief

The Kirki WordPress plugin is a page builder tool that allows administrators to design website layouts. Before version 6.3.0, the plugin failed to properly verify user permissions when retrieving page content, allowing unauthenticated visitors to read private, draft, pending, or trashed pages that should not be publicly visible. An attacker could exploit this to access sensitive content that was intended to be confidential.

Technical details

The vulnerability is an authorization bypass in the Kirki plugin's REST API endpoint /wp-json/kirki/v1/frontend/collection. The plugin accepts a kirki_data parameter containing a nested post_id field but only validates permissions against top-level parameters (post_id and context), not the nested post_id value used to actually load and render content. This allows unauthenticated attackers to request restricted posts via the nested parameter and receive fully rendered page markup, bypassing WordPress's standard permission checks. The vulnerability affects versions 6.2.1 through 6.2.5 and was fixed in version 6.3.0. No authentication or user interaction is required for exploitation.

Affected products

  • Kirki Kirki 6.2.1 through 6.2.5

Timeline

  • 2026-09-07: disclosed
  • 2026-09-09: patched: Fixed in version 6.3.0

References