CVE-2026-74992Disclosure

LOWCVSS 6.8 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all unwanted files after extracting them, allowing such users to upload arbitrary files to a web accessible directory, leading to Stored XSS as well as RCE on some server configurations.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-20: 2Technical Details · 2026-08-20: 208-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-74992 The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all un… https://www.cve.org/CVERecord?id=CVE-2026-74992 ----- Traducción: CVE-2026-74992 El … https://infoflow.cloud`

    Post summary

    The tweet announces the disclosure of CVE-2026-74992 affecting the Kirki WordPress plugin, noting a validation flaw but providing no PoC, exploit, or mitigation details.

    0000034
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-74992 The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all un… https://www.cve.org/CVERecord?id=CVE-2026-74992

    Post summary

    The snippet reports that the Kirki WordPress plugin, before version 6.2.3, fails to validate files contained in archives uploaded by users with the Editor role, potentially exposing the site to malicious content.

    00000908
    58.0K followersView on X

Explore more