CVE-2026-18335: Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Unauthenticated Blind Server-Side Request Forgery via 'kirki_data' Parameter
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 6.2.0 via the 'kirkidata' Parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Affected Software
Event History
Frequently Asked Questions
Which installations require remediation?
All versions of the Kirki plugin up to and including 6.2.0 are affected.
Does an attacker need a WordPress account or user interaction to exploit this issue?
No. The vulnerability is exploitable remotely without privileges or user interaction, although the CVSS assessment rates attack complexity as high.
What access could a successful attacker gain through the vulnerable site?
An attacker can cause the web application to make requests to arbitrary locations. This may allow querying or modifying information exposed by internal services.