Sceawere

Vulnerability Detail

CVE-2026-103065UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Kirki Improper Quantity Validation

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
4h ago
Vendor
Themeum
Product
Kirki
Attack Type
Improper Validation of Specified Quantity in Input
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-10-03T15:16:35.300Z",
  "pubdate": "2026-10-03T15:16:35.300Z",
  "executiveSummary": "The Kirki framework for WordPress is affected by an Improper Validation of Specified Quantity in Input vulnerability, leading to unauthorized access to restricted functionalities.\nThis vulnerability is classified as an Access Control issue, where the framework fails to adequately enforce authorization constraints when handling user-supplied quantity inputs.\nThe vulnerability affects Kirki versions from n/a through 6.3.1.\nAn unauthenticated or low-privileged attacker could potentially exploit this flaw to bypass established Access Control Lists (ACLs).\nSuccessful exploitation allows an attacker to interact with backend functions or administrative capabilities that should be restricted to higher-privileged users, potentially leading to unauthorized data modification, configuration changes, or unauthorized actions within the WordPress environment.\nThe risk is significant as it undermines the integrity of the plugin's access control architecture, potentially allowing complete administrative bypass within the scope of the affected functions.",
  "technicalDetails": "The vulnerability originates from a failure to correctly sanitize or validate input fields that specify quantities within the Kirki framework. Specifically, the framework incorrectly handles user-supplied parameters used to define or limit operations.\nBy manipulating these quantity-based parameters, an attacker can coerce the application into bypassing internal checks intended to verify whether the requester possesses the appropriate privileges or permissions to execute a specific function. This is a manifestation of improper input validation leading to broken access control.\nThe root cause lies in the application's logic, which assumes that the supplied quantity parameter is safe or that its value is solely for business logic, failing to recognize that this parameter can influence the decision-making process of the framework's authorization engine.\nTo exploit this, an attacker identifies endpoints or function calls within Kirki that accept a quantity argument and interact with underlying system or administrative settings. By crafting a specific input value—likely a boundary value, a negative value, or an unexpectedly large number—the attacker can trigger an error or a logic branch that the developers did not intend to be reachable by unauthorized users.\nThis manipulation bypasses the intended ACLs. The framework, misled by the invalid input, erroneously assumes the request is legitimate and executes the protected function.\nThe attack flow proceeds as follows: 1. Identification of target functionality in Kirki that processes quantity inputs. 2. Crafting a malicious request containing a manipulated quantity parameter. 3. Submission of the crafted request to the vulnerable endpoint. 4. The application processes the input, bypasses the ACL, and executes the privileged action.\nThe scope of impact post-exploitation depends on the function reached; however, since the vulnerability allows accessing functionality not properly constrained by ACLs, an attacker could potentially gain unauthorized control over plugin-specific features, configurations, or data, exceeding the privileges assigned to their current session."
}
CVE-2026-103065: Kirki Improper Quantity Validation (HIGH Severity, CVSS: 8.2) | Sceawere