CVE-2026-77754: Kirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_apis
Published Aug 26, 2026
·Updated
The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJAX actions, allowing unauthenticated users to retrieve the email addresses of registered users and comment authors, as well as non-public page content and settings.
Affected Software
1 affected component
Kirki WordPress plugin<6.0.14
Event History
Aug 26, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are exposed to this issue?
WordPress sites using the Kirki plugin before version 6.0.14 are affected. The affected functionality is a public AJAX action with endpoints that lack a capability check.
2
Does an attacker need an account or special permissions?
No. The issue can be exploited by an unauthenticated user, so no WordPress account or privileges are required.
3
What information could be disclosed?
An attacker may retrieve email addresses for registered users and comment authors. Non-public page content and settings may also be exposed.