WordPress Plugin Vulnerabilities

Kirki < 6.1.0 - Unauthenticated Sensitive Data Disclosure via context Parameter

Description

The plugin is vulnerable to Insecure Direct Object Reference via the 'context' parameter due to missing validation on a user-controlled key. This makes it possible for unauthenticated attackers to read the full title, content, and excerpt of any WordPress post — including draft, pending, privately published, password-protected, and trashed posts — regardless of author, by supplying an arbitrary post ID via the context parameter alongside an attacker-controlled block template.

Affects Plugins

Fixed in 6.1.0

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Abu Hurayra (HurayraIIT)
Verified
No

Timeline

Publicly Published
2026-07-23 (about 1 month ago)
Added
2026-07-24 (about 30 days ago)
Last Updated
2026-07-24 (about 30 days ago)

Other