CVE-2026-84221: Unknown Kirki
Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.
Affected products
- Unknown Kirki: from 6.0.0, before 6.3.0 (fixed in 6.3.0)
Published 2026-09-05. Last modified 2026-09-08.