CVE-2026-77754
Kirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_apis
CVSS Score
5.3
EPSS Score
0.2%
EPSS Percentile
7th
The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJAX actions, allowing unauthenticated users to retrieve the email addresses of registered users and comment authors, as well as non-public page content and settings.
| Vendor | unknown |
| Product | kirki |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown kirki
Be the first to know when new medium vulnerabilities affecting unknown kirki are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Kirki
0 < 6.0.14
References
Credits
Vaibhav Narkhede WPScan