CVE-2026-18347: Kirki <= 6.1.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'context' Parameter
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.1.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to read arbitrary user metadata and sensitive user record fields — including email address, assigned roles, registration date, and any usermeta values — belonging to any WordPress user including administrators, by supplying a target user ID with a user-type context to the frontend collection endpoint.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPressto a version that resolves this vulnerability.Fixed in 6.1.1 - Compensating control
Restrict access to the frontend collection endpoint that accepts the 'context' parameter so that only properly authorized users can query user metadata (authorization enforcement at the application/WAF layer until the vulnerable version is patched).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18347?
The severity of CVE-2026-18347 is medium with a CVSS score of 4.3.
What type of vulnerability is CVE-2026-18347?
CVE-2026-18347 is an authorization bypass vulnerability affecting the Kirki plugin.
How do I fix CVE-2026-18347?
To address CVE-2026-18347, update the Kirki plugin to version 6.1.2 or later.
What impact does CVE-2026-18347 have?
CVE-2026-18347 can lead to the disclosure of sensitive information by authenticated users who should not have access.
Which software is affected by CVE-2026-18347?
The vulnerability affects all versions of the Kirki plugin up to and including version 6.1.1.