Sceawere

Vulnerability Detail

CVE-2026-18347UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Kirki Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
themeum
Product
Kirki – Freeform Page Builder, Website Builder & Customizer
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.1.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to read arbitrary user metadata and sensitive user record fields — including email address, assigned roles, registration date, and any user_meta values — belonging to any WordPress user including administrators, by supplying a target user ID with a user-type context to the frontend collection endpoint.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-16T07:16:30.787Z",
  "pubdate": "2026-08-16T07:16:30.787Z",
  "executiveSummary": "An authorization bypass vulnerability has been identified in the Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress in all versions up to, and including, 6.1.1. The flaw stems from insufficient access control enforcement on the frontend collection endpoint, failing to properly verify whether a requesting user possesses the authorization required to execute specific actions. This security deficiency allows authenticated attackers with custom-level access and above to improperly retrieve sensitive data. The potential business and operational impact includes the complete exposure of confidential user records and metadata across the entire WordPress user base, including high-privileged accounts such as administrators. Exploitation requires authenticated access at the custom user level or higher, granting malicious actors the ability to harvest critical intelligence such as email addresses, assigned security roles, and user registration dates, which can facilitate subsequent targeted attacks or privilege escalation vectors within the compromised WordPress environment.",
  "technicalDetails": "The vulnerability resides within the access control logic of the Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress. Specifically, the root cause is a failure in authorization validation, where the application does not adequately ensure that the user initiating a request is permitted to perform the requested operation on the frontend collection endpoint. Affected versions include all releases up to, and including, 6.1.1. Exploitation of this vulnerability requires network exposure accessible to authenticated users holding custom-level access or higher. The authentication requirement is relatively low, as attackers only need baseline privileges within the application scope. The attack vector involves an authenticated actor interacting directly with the frontend collection endpoint. By supplying a targeted user ID paired with a user-type context within the request parameters, the attacker bypasses intended authorization boundaries. The vulnerable component fails to restrict data access based on the principle of least privilege, causing the backend logic to process the request and return sensitive records. Post-exploitation impact encompasses the unauthorized disclosure of arbitrary user metadata and sensitive user record fields. This includes confidential data elements such as email addresses, assigned security roles, exact user registration dates, and arbitrary user_meta values associated with any WordPress user. Because this mechanism does not exclude high-privileged accounts, attackers can systematically harvest administrator-level metadata, exposing critical infrastructural intelligence that can be leveraged for further compromise."
}
CVE-2026-18347: Kirki Authorization Bypass Vulnerability (MEDIUM Severity, CVSS: 4.3) - Sceawere