CVE detail
CVE-2026-18347
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.1.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to read arbitrary user metadata and sensitive user record fields — including email address, assigned roles, registration date, and any user_meta values — belonging to any WordPress user including administrators, by supplying a target user ID with a user-type context to the frontend collection endpoint.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 12
- within the 30d window
- Peak daily
- 12
- highest bucket
Evidence
Source links by recency
12 source links · newest first
- https://www.wordfence.com/threat-intel/vulnerabilities/id/fa1e0bcd-f881-4b01-b802-7cb18a22a07f?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comAug 16, 2026, 7:16 AM - https://plugins.trac.wordpress.org/changeset?reponame=&old=3629933%40kirki&new=3629933%40kirkiplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/kirki/tags/6.1.1/includes/HelperFunctions.php#L1098plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/kirki/tags/6.1.1/includes/Ajax/Users.php#L227plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/kirki/tags/6.1.1/includes/API/Frontend/Controllers/FrontendRESTController.php#L82plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/kirki/tags/6.1.1/includes/API/Frontend/Controllers/FrontendRESTController.php#L42plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/kirki/tags/6.1.1/includes/API/Frontend/Controllers/CollectionController.php#L97plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.9/includes/HelperFunctions.php#L1098plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.9/includes/Ajax/Users.php#L227plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.9/includes/API/Frontend/Controllers/FrontendRESTController.php#L82plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.9/includes/API/Frontend/Controllers/FrontendRESTController.php#L42plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 7:16 AM - https://plugins.trac.wordpress.org/browser/kirki/tags/6.0.9/includes/API/Frontend/Controllers/CollectionController.php#L97plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 16, 2026, 7:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-69148CVSS 7.1 · High
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id a…
- CVE-2026-69146CVSS 6.5 · Medium
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_…
- CVE-2026-75109CVSS 7.1 · High
Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt other users' workloads by te…
- CVE-2026-75108CVSS 5.3 · Medium
Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe and wake assets they are not g…
- CVE-2026-54356CVSS 7.1 · High
Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/cont…
- CVE-2026-63669CVSS 6.5 · Medium
ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission…