WordPress Plugin Vulnerabilities
Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions
Description
The plugin does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticated users to run any shortcode registered on the site, which on a default install leads to disclosure of the site administrator's email address and an arbitrary-recipient mail relay from the victim's domain.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
INJECTION
OWASP top 10
CVSS
Miscellaneous
Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-10 (about 24 days ago)
Added
2026-08-10 (about 23 days ago)
Last Updated
2026-09-02 (about 3 hours ago)