
株式会社mgn@mgn_jpn
🚨 Kirki に脆弱性(深刻度 中) 50万サイト以上が利用 / CVSS 5.4 修正版 6.2.1 が公開済み https://shindan.m-g-n.me/alerts/cve-2026-18335/
0001099
272 followersView on X
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 6.2.0 via the 'kirki_data' Parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🚨 Kirki に脆弱性(深刻度 中) 50万サイト以上が利用 / CVSS 5.4 修正版 6.2.1 が公開済み https://shindan.m-g-n.me/alerts/cve-2026-18335/