The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticated users to run any shortcode registered on the site, which on a default install leads to disclosure of the site administrator's email address and an arbitrary-recipient mail relay from the victim's domain.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-12 12:17
Updated : 2026-08-26 16:30
NVD link : CVE-2026-16747
Mitre link : CVE-2026-16747
CVE.ORG link : CVE-2026-16747
JSON object : View
Products Affected
No product.
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
