CVE-2026-84220: Kirki < 6.3.2 - Unauthenticated Arbitrary Shortcode Execution via Comments Collection
The Kirki WordPress plugin before 6.3.2 does not prevent shortcodes held in comments from being executed when it renders them, and displays comments regardless of their moderation status, allowing unauthenticated visitors to run shortcodes registered on the site and to read private custom fields of the page being viewed.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and what access do they need?
Unauthenticated visitors can exploit it; no account, privileges, or user interaction are required. Exploitation requires a site with Kirki before 6.3.2 and shortcodes registered on that site.
What information or impact can result from exploitation?
An attacker can cause registered shortcodes to execute through comments. The issue can expose private custom fields associated with the page being viewed.
Are unapproved comments relevant to exposure?
Yes. The affected behavior renders comments regardless of their moderation status, so comment moderation does not prevent those comments from being displayed and processed.
What version resolves the issue?
Upgrade Kirki to version 6.3.2 or later. Versions before 6.3.2 are affected.