Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 19 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to view all Kirki frontend forms and read stored visitor form submission data, including contact details, messages, and any other visitor-provided information submitted through site forms. | |
| Title | Kirki <= 6.0.6 - Missing Authorization to Authenticated (Subscriber+) Sensitive Form Submission Data Exposure via 'kirki_wp_admin_get_apis' Action | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-19T19:35:37.550Z
Reserved: 2026-05-07T13:14:53.291Z
Link: CVE-2026-8096
Updated: 2026-05-19T19:35:32.017Z
Status : Received
Published: 2026-05-19T19:16:51.743
Modified: 2026-05-19T19:16:51.743
Link: CVE-2026-8096
No data.
OpenCVE Enrichment
Updated: 2026-05-19T20:30:13Z