CVE-2026-77754
Received Received - Intake

Kirki Plugin Unauthenticated Data Exposure Vulnerability

Vulnerability report for CVE-2026-77754, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: WPScan

Description

The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJAX actions, allowing unauthenticated users to retrieve the email addresses of registered users and comment authors, as well as non-public page content and settings.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
aristath kirki to 6.0.14 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Kirki WordPress plugin before version 6.0.14 allows unauthenticated users to access sensitive data through public AJAX endpoints. Specifically, it exposes email addresses of registered users and comment authors, as well as non-public page content and settings.

Impact Analysis

Unauthenticated attackers could retrieve private user data like email addresses and non-public page content. This could lead to privacy breaches, spam, or targeted phishing attacks against users.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized access to personal data (emails) and HIPAA if non-public health-related content is exposed. It undermines data protection requirements for user privacy and security.

Mitigation Strategies

Update the Kirki WordPress plugin to version 6.0.14 or later to address the capability check issue in its AJAX endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77754. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart