SecAlerts
k

kirki

Security Risk Profile

38
/100
low

Security Risk Score

Comprehensive risk assessment based on 9 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from May 19, 2026 to present

9
Total CVEs
2
Critical+High
1
Exploited
2
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
38/100
low
⚠️ 1 Active Exploits🆕 1Fresh (<7d)📈 3 in Last 30 Days

Severity Distribution

Critical
1
High
1
Medium
5
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
3

Age Distribution

Common Weaknesses (CWE)

1
Infoleak
2
2
XSS
1

Most Affected Products

1. Kirki WordPress plugin2
2. Kirki Kirki2
3. Kirki Kirki – Freeform Page Builder, Website Builder & Customizer1
4. Kirki WordPress plugin Kirki1
5. Kirki Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress1

Recent Vulnerabilities

See more →
CVE-2026-84222
unknown

Kirki 6.2.1 - 6.2.5 - Unauthenticated Non-Public Post Content Disclosure via 'kirki_data' Parameter

Sep 9, 2026🔧 No Patch
CVE-2026-77754
CVSS 5.3medium

Kirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_apis

Aug 26, 2026🔧 No Patch
CVE-2026-16974
CVSS 6.4medium

Kirki - Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta Shortcode

Aug 11, 2026🔧 No Patch
CVE-2026-12472
CVSS 5.3medium

Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters

Jul 2, 2026🔧 No Patch
CVE-2026-12122
CVSS 5.3medium

Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action

Jul 2, 2026🔧 No Patch
bleepingcomputer-20260602221257
unknown

Critical Kirki flaw exploited to hijack WordPress admin accounts

Jun 2, 2026⚠ Exploited🔧 No Patch
CVE-2026-8206
CVSS 9.8EPSS 0%critical

Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'

Jun 2, 2026🔧 No Patch
CVE-2026-8073
CVSS 7.5EPSS 0%high

Kirki <= 6.0.6 - Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIP

May 19, 2026🔧 No Patch
CVE-2026-8096
CVSS 6.5EPSS 0%medium

Kirki <= 6.0.6 - Missing Authorization to Authenticated (Subscriber+) Sensitive Form Submission Data Exposure via 'kirki_wp_admin_get_apis' Action

May 19, 2026🔧 No Patch

Monitor kirki in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.