The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13.
Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.