CVE-2026-84224
Received Received - Intake

Kirki Plugin URL Fetching Host Validation Bypass

Vulnerability report for CVE-2026-84224, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: WPScan

Description

The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Kirki 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Kirki WordPress plugin before version 6.3.2. It allows users with editor-level access or higher to make the website send requests to internal services that are normally unreachable. The plugin does not check the host of a URL before fetching it, so attackers can exploit this to probe internal systems and determine which ones are active based on the responses.

Detection Guidance

To detect this vulnerability, check if your Kirki WordPress plugin version is below 6.3.2. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files for version info. Monitor network logs for unusual internal requests originating from the plugin.

Impact Analysis

If you use the vulnerable version of the Kirki plugin, attackers with editor access or higher could map your internal network by sending requests to internal services. This could reveal sensitive information about your systems and potentially lead to further attacks if internal services are compromised.

Compliance Impact

This vulnerability may impact compliance by exposing internal systems, which could lead to unauthorized access or data breaches. GDPR requires protecting personal data, and HIPAA requires safeguarding health information. A breach or unauthorized access could result in violations and penalties.

Mitigation Strategies

Update the Kirki WordPress plugin to version 6.3.2 or later to address the URL validation issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84224. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart