WordPress Plugin Vulnerabilities

Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID

Description

The plugin does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.

Proof of Concept

Affects Plugins

Fixed in 6.3.0

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Original Researcher
Karthik Ramakrishnan
Submitter
Karthik Ramakrishnan
Verified
Yes

Timeline

Publicly Published
2026-09-03 (about 2 days ago)
Added
2026-09-03 (about 1 day ago)
Last Updated
2026-09-03 (about 1 day ago)

Other