CVE-2026-8096: Kirki <= 6.0.6 - Missing Authorization to Authenticated (Subscriber+) Sensitive Form Submission Data Exposure via 'kirki_wp_admin_get_apis' Action
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to view all Kirki frontend forms and read stored visitor form submission data, including contact details, messages, and any other visitor-provided information submitted through site forms.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8096?
The severity of CVE-2026-8096 is classified as medium due to the authorization bypass risk allowing sensitive data exposure.
How do I fix CVE-2026-8096?
To fix CVE-2026-8096, update the Kirki plugin to version 6.0.7 or later to address the vulnerability.
What type of vulnerability is CVE-2026-8096?
CVE-2026-8096 is an authorization bypass vulnerability affecting the Kirki plugin for WordPress.
What versions of Kirki are affected by CVE-2026-8096?
All versions of the Kirki plugin up to and including 6.0.6 are affected by CVE-2026-8096.
Who is impacted by CVE-2026-8096?
Authenticated users with Subscriber+ roles using outdated versions of Kirki are impacted by CVE-2026-8096.