WordPress Plugin Vulnerabilities
Kirki < 6.1.0 - Unauthenticated Sensitive Data Disclosure via context Parameter
Description
The plugin is vulnerable to Insecure Direct Object Reference via the 'context' parameter due to missing validation on a user-controlled key. This makes it possible for unauthenticated attackers to read the full title, content, and excerpt of any WordPress post — including draft, pending, privately published, password-protected, and trashed posts — regardless of author, by supplying an arbitrary post ID via the context parameter alongside an attacker-controlled block template.
Affects Plugins
References
Classification
Type
IDOR
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Abu Hurayra (HurayraIIT)
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-07-23 (about 1 month ago)
Added
2026-07-24 (about 30 days ago)
Last Updated
2026-07-24 (about 30 days ago)