CVE-2026-84221
Description
The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.
References (1)
Source: contact@wpscan.com
Timeline
No history available yet.