Sceawere
Vulnerability Detail
CVE-2026-84224UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Kirki Plugin SSRF Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.1
- Creation Date
- 3h ago
- Vendor
- Unknown
- Product
- Kirki
- Attack Type
- CWE-918 Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.1",
"pubDate": "2026-10-09T09:17:10.000Z",
"pubdate": "2026-10-09T09:17:10.000Z",
"executiveSummary": "The Kirki WordPress plugin, in versions prior to 6.3.2, is susceptible to a Server-Side Request Forgery (SSRF) vulnerability. This security flaw originates from improper input validation regarding the host component of user-supplied URLs passed to the plugin's internal request handling mechanisms.\nThe vulnerability allows an authenticated attacker with at least editor-level privileges to force the WordPress server to initiate unauthorized HTTP requests to arbitrary destinations. This enables interaction with internal network resources that are otherwise shielded from the public internet by firewalls or network segmentation.\nThe risk implications are significant, as the vulnerability can be leveraged to conduct internal reconnaissance, port scanning, or to interact with unprotected local services (e.g., metadata services, internal APIs, or databases). By observing variations in server responses, an attacker can confirm the existence and status of internal network assets. Successful exploitation requires an attacker to possess valid editor-level credentials, limiting the threat to authorized users with elevated permissions.",
"technicalDetails": "The vulnerability resides in the request processing logic of the Kirki plugin, which fails to implement a robust allowlist or blocklist validation mechanism for the host header or URL components before performing server-side fetch operations. Specifically, the component responsible for processing remote resources does not sanitize or validate the target host, allowing the application to resolve and connect to internal IP addresses and services.\nThe attack flow begins when an attacker, authenticated as an editor, supplies a crafted URL to the vulnerable plugin function. Because the plugin does not verify if the destination host is an external or internal entity, the server initiates an outgoing request on behalf of the attacker. By observing the timing or the specific content of the error messages and response headers returned by the server, an attacker can determine the status of internal services—a technique often referred to as blind or semi-blind SSRF.\nThe root cause is the lack of a destination validation layer in the plugin's URL handling code. The plugin acts as a proxy, effectively bridging the gap between an authenticated user and the internal network architecture of the hosting environment. This permits the interaction with services listening on localhost (127.0.0.1) or internal network segments (e.g., 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16) that are not exposed to the public.\nThis SSRF can lead to serious post-exploitation impacts, including unauthorized access to internal management interfaces, cloud instance metadata services (such as the AWS Instance Metadata Service, which can leak sensitive tokens), or sensitive configuration endpoints that lack further authentication. Furthermore, the ability to probe internal services allows an attacker to map the internal network topology, providing a roadmap for further lateral movement within the hosting infrastructure. The vulnerability is present in all versions prior to 6.3.2 and relies entirely on the plugin's logic for executing the fetch, rather than any secondary misconfiguration in the WordPress core itself."
}