CVE-2026-84222: Kirki 6.2.1 - 6.2.5 - Unauthenticated Non-Public Post Content Disclosure via 'kirki_data' Parameter

Published Sep 9, 2026
·
Updated

The Kirki WordPress plugin before 6.3.0 does not check whether the requester is allowed to read a post before rendering and returning its page content, allowing unauthenticated users to retrieve the content of pages that are not publicly available, such as private, draft, pending and trashed ones.

Affected Software

1 affected component
Kirki WordPress plugin<6.3.0

Event History

Sep 9, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Which installations are affected?

Kirki versions before 6.3.0 are affected. The issue concerns WordPress sites using the Kirki plugin where non-public pages may contain sensitive content.

2

Does an attacker need an account or special permissions?

No. An unauthenticated requester can exploit the issue because the plugin does not verify whether the requester is permitted to read the requested post before returning its content.

3

What content could be exposed?

The disclosed content can include pages that are not publicly available, including private, draft, pending, and trashed pages.

4

What should be done if an immediate upgrade is not possible?

The provided information does not specify a workaround. Restricting exposure of the affected site until Kirki can be updated may reduce unauthenticated access, but no specific mitigation is stated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203