CVE-2026-16747: Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions
The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticated users to run any shortcode registered on the site, which on a default install leads to disclosure of the site administrator's email address and an arbitrary-recipient mail relay from the victim's domain.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/kirkito a version that resolves this vulnerability.Fixed in 6.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16747?
The severity of CVE-2026-16747 is rated medium with a score of 6.5.
How do I fix CVE-2026-16747?
To fix CVE-2026-16747, update the Kirki WordPress plugin to version 6.2.1 or later.
What type of attack does CVE-2026-16747 facilitate?
CVE-2026-16747 allows unauthenticated users to execute arbitrary shortcodes via insecure front-end form submissions.
What versions of the Kirki plugin are affected by CVE-2026-16747?
CVE-2026-16747 affects versions of the Kirki WordPress plugin prior to 6.2.1.
What is the primary risk posed by CVE-2026-16747?
The primary risk of CVE-2026-16747 is the potential for unauthorized disclosure of sensitive information through shortcode execution.