CVE-2026-84222: Kirki 6.2.1 - 6.2.5 - Unauthenticated Non-Public Post Content Disclosure via 'kirki_data' Parameter
The Kirki WordPress plugin before 6.3.0 does not check whether the requester is allowed to read a post before rendering and returning its page content, allowing unauthenticated users to retrieve the content of pages that are not publicly available, such as private, draft, pending and trashed ones.
Affected Software
Event History
Frequently Asked Questions
Which installations are affected?
Kirki versions before 6.3.0 are affected. The issue concerns WordPress sites using the Kirki plugin where non-public pages may contain sensitive content.
Does an attacker need an account or special permissions?
No. An unauthenticated requester can exploit the issue because the plugin does not verify whether the requester is permitted to read the requested post before returning its content.
What content could be exposed?
The disclosed content can include pages that are not publicly available, including private, draft, pending, and trashed pages.
What should be done if an immediate upgrade is not possible?
The provided information does not specify a workaround. Restricting exposure of the affected site until Kirki can be updated may reduce unauthenticated access, but no specific mitigation is stated.