CVE-2026-84221: Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID

Published Sep 5, 2026
·
Updated

The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.

Affected Software

1 affected component
WordPress Kirki<6.3.0

Event History

Sep 5, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated WordPress user with editor-level access or higher can exploit it. Sites where editor accounts are limited to trusted users have a narrower exposure than sites that grant editor access to less-trusted contributors.

2

What access does an attacker need?

The attacker needs an account with at least the Editor role and must be able to provide a crafted identifier through the Content Manager field. The issue is not described as exploitable by unauthenticated visitors or lower-privileged users.

3

What data could be exposed?

An attacker can append arbitrary SQL and read database contents. This may include user credentials, according to the advisory.

4

Which versions need remediation?

Kirki versions 6.0.0 through 6.2.5 are affected, and the issue is fixed in version 6.3.0. Upgrade to 6.3.0 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203