WordPress Plugin Vulnerabilities

Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions

Description

The plugin does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticated users to run any shortcode registered on the site, which on a default install leads to disclosure of the site administrator's email address and an arbitrary-recipient mail relay from the victim's domain.

Proof of Concept

Affects Plugins

Fixed in 6.2.1

References

Classification

Type
INJECTION
OWASP top 10

Miscellaneous

Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-10 (about 24 days ago)
Added
2026-08-10 (about 23 days ago)
Last Updated
2026-09-02 (about 3 hours ago)

Other