CVE-2026-77754 PUBLISHED

Kirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_apis

Assigner: WPScan
Reserved: 21.08.2026 Published: 26.08.2026 Updated: 26.08.2026

The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJAX actions, allowing unauthenticated users to retrieve the email addresses of registered users and comment authors, as well as non-public page content and settings.

Product Status

Vendor Unknown
Product Kirki
Versions Default: unaffected
  • affected from 0 to 6.0.14 (excl.)

Credits

  • Vaibhav Narkhede finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE