Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kirki
Kirki kirki Wordpress Wordpress wordpress |
|
| Vendors & Products |
Kirki
Kirki kirki Wordpress Wordpress wordpress |
Wed, 12 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-74 | |
| Metrics |
ssvc
|
Wed, 12 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticated users to run any shortcode registered on the site, which on a default install leads to disclosure of the site administrator's email address and an arbitrary-recipient mail relay from the victim's domain. | |
| Title | Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-12T12:12:18.556Z
Reserved: 2026-07-23T12:09:27.936Z
Link: CVE-2026-16747
Updated: 2026-08-12T12:12:03.949Z
Status : Received
Published: 2026-08-12T12:17:47.053
Modified: 2026-08-12T13:17:19.900
Link: CVE-2026-16747
No data.
OpenCVE Enrichment
Updated: 2026-08-12T23:00:05Z
-
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')