CVE-2026-84222: CWE-200 Information Exposure in Kirki
CVE-2026-84222 is an information exposure vulnerability in the Kirki WordPress plugin versions before 6.3.0. The plugin fails to verify if a requester has permission to read a post before rendering and returning its content. This allows unauthenticated users to access content of pages that are not publicly available, including private, draft, pending, and trashed pages.
AI Analysis
Technical Summary
The Kirki WordPress plugin prior to version 6.3.0 contains a vulnerability classified as CWE-200 (Information Exposure). It does not perform access control checks to verify whether the requester is authorized to view a post before rendering and returning the page content. Consequently, unauthenticated users can retrieve the content of posts that should be restricted, such as private, draft, pending, and trashed pages. This vulnerability affects version 6.2.1 explicitly, and presumably earlier versions before 6.3.0.
Potential Impact
Unauthenticated attackers can access sensitive content that is intended to be private or restricted, including unpublished or deleted posts. This exposure can lead to leakage of confidential or sensitive information stored in these pages. There is no indication of active exploitation in the wild at this time.
Mitigation Recommendations
No official patch or remediation guidance is currently confirmed. Users should upgrade to Kirki version 6.3.0 or later once available, as the vulnerability affects versions before 6.3.0. Until then, restrict access to the plugin or implement additional access controls at the server or WordPress level to prevent unauthorized content retrieval. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2026-84222: CWE-200 Information Exposure in Kirki
Description
CVE-2026-84222 is an information exposure vulnerability in the Kirki WordPress plugin versions before 6.3.0. The plugin fails to verify if a requester has permission to read a post before rendering and returning its content. This allows unauthenticated users to access content of pages that are not publicly available, including private, draft, pending, and trashed pages.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Kirki WordPress plugin prior to version 6.3.0 contains a vulnerability classified as CWE-200 (Information Exposure). It does not perform access control checks to verify whether the requester is authorized to view a post before rendering and returning the page content. Consequently, unauthenticated users can retrieve the content of posts that should be restricted, such as private, draft, pending, and trashed pages. This vulnerability affects version 6.2.1 explicitly, and presumably earlier versions before 6.3.0.
Potential Impact
Unauthenticated attackers can access sensitive content that is intended to be private or restricted, including unpublished or deleted posts. This exposure can lead to leakage of confidential or sensitive information stored in these pages. There is no indication of active exploitation in the wild at this time.
Mitigation Recommendations
No official patch or remediation guidance is currently confirmed. Users should upgrade to Kirki version 6.3.0 or later once available, as the vulnerability affects versions before 6.3.0. Until then, restrict access to the plugin or implement additional access controls at the server or WordPress level to prevent unauthorized content retrieval. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-01T11:50:25.666Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa0f7c4acd9273b49d857cf
Added to database: 09/09/2026, 06:08:04 UTC
Last enriched: 09/09/2026, 06:23:02 UTC
Last updated: 09/09/2026, 06:38:26 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.