WordPress Plugin Vulnerabilities
Kirki < 6.0.7 - Subscriber+ Sensitive Data Exposure via kirki_wp_admin_get_apis Action
Description
The plugin is vulnerable to authorization bypass via the `kirki_wp_admin_get_apis` AJAX action due to a missing capability check. This makes it possible for authenticated attackers with Subscriber-level access and above to view all frontend forms and read stored visitor form submission data, including contact details and messages.
Affects Plugins
References
Classification
Type
SENSITIVE DATA DISCLOSURE
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Z3no
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-05-19 (about 2 months ago)
Added
2026-05-19 (about 2 months ago)
Last Updated
2026-05-19 (about 2 months ago)