What is CVE-2026-16747?
The Kirki WordPress plugin before version 6.2.1 lacks proper authorization on its front-end form submission REST routes, allowing unauthenticated attackers to execute arbitrary registered shortcodes via attacker-controlled input. On default installations, this vulnerability leads to information disclosure. Immediate update to version 6.2.1 or later is required.
Azərbaycanca: Kirki WordPress plaginində (6.2.1-dən əvvəlki versiyalar) front-end form REST marşrutlarında authorizasiya zəifliyi aşkarlanıb. Bu, autentifikasiya olunmamış istifadəçilərə saytda qeydiyyatdan keçmiş istənilən shortcode-i işə salmağa imkan verir ki, bu da default quraşdırmada məlumat sızmasına səbəb olur. Plagin dərhal 6.2.1 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What risk does CVE-2026-16747 pose in the Kirki WordPress plugin?
This vulnerability allows unauthenticated attackers to execute arbitrary registered shortcodes via the front-end form submission REST routes. On default installations, this leads to information disclosure.
To which version should the Kirki plugin be updated to mitigate CVE-2026-16747?
The plugin should be immediately updated to version 6.2.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.