Sceawere

Vulnerability Detail

CVE-2026-84220UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Kirki Shortcode Execution Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.8
Creation Date
2h ago
Vendor
Unknown
Product
Kirki
Attack Type
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The Kirki WordPress plugin before 6.3.2 does not prevent shortcodes held in comments from being executed when it renders them, and displays comments regardless of their moderation status, allowing unauthenticated visitors to run shortcodes registered on the site and to read private custom fields of the page being viewed.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.8",
  "pubDate": "2026-10-09T09:17:09.857Z",
  "pubdate": "2026-10-09T09:17:09.857Z",
  "executiveSummary": "The Kirki WordPress plugin, in versions prior to 6.3.2, contains a critical security vulnerability involving the improper handling of shortcodes within comment sections. This flaw allows unauthenticated attackers to execute arbitrary shortcodes registered on the WordPress site. By circumventing the standard comment moderation workflow, the plugin displays these comments prematurely, granting unauthorized access to sensitive information. The primary impact includes the unauthorized disclosure of private custom fields associated with the targeted page. This vulnerability poses a significant risk to data confidentiality and site integrity, as it enables remote attackers to interact with site features and extract restricted metadata without requiring prior authentication or administrative privileges.",
  "technicalDetails": "The vulnerability originates from a failure to sanitize or filter input within the Kirki plugin's comment rendering logic. Specifically, the plugin does not implement the necessary restrictions to prevent the processing of WordPress shortcodes contained within user-submitted comments. In a secure WordPress environment, shortcodes are typically parsed only within intended contexts; however, Kirki forces the rendering of these shortcodes regardless of the comment's moderation state.\nThe attack flow begins when an unauthenticated attacker submits a crafted comment containing a malicious or sensitive shortcode, such as those that might retrieve protected post metadata. Because the plugin displays comments regardless of their moderation status, the malicious shortcode is executed immediately upon the page load, even if the comment has not been approved by an administrator.\nUpon execution, the shortcode processor renders the output directly into the page's HTML structure. If an attacker leverages shortcodes designed to access custom fields or private page data, the plugin facilitates the leakage of this sensitive information back to the attacker's browser session. Since this process occurs on the server side, the attacker can extract data that is typically restricted to logged-in users or administrators.\nAffected versions include all releases of Kirki prior to 6.3.2. The exploitation does not require elevated privileges or authentication, as the vulnerable component processes the input at the entry point of the comment rendering pipeline. The lack of an access control check against the comment status ensures that the malicious payload is triggered persistently until the comment is manually removed by an administrator. This vulnerability demonstrates a failure in secure coding practices related to input validation and the principle of least privilege, specifically concerning the interaction between public-facing comment forms and sensitive internal shortcode parsing functions."
}
CVE-2026-84220: Kirki Shortcode Execution Vulnerability (MEDIUM Severity, CVSS: 4.8) | Sceawere