
CVE-2026-18347 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.1.1… https://www.cve.org/CVERecord?id=CVE-2026-18347
Post summary
A new WordPress plugin flaw affects all versions of Kirki up to 6.1.1, enabling an authorization bypass that could allow attackers to gain elevated privileges.
