WordPress Plugin Vulnerabilities

Kirki < 6.3.2 - Editor+ Blind SSRF via Remote Template URL

Description

The plugin does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response.

Proof of Concept

Affects Plugins

Fixed in 6.3.2

References

Classification

Type
SSRF
OWASP top 10
CWE

Miscellaneous

Original Researcher
Mohammed Abd Alrahman
Submitter
Mohammed Abd Alrahman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-10-09 (about 10 hours ago)
Added
2026-10-09 (about 2 hours ago)
Last Updated
2026-10-09 (about 2 hours ago)

Other