What is CVE-2026-18347?
CVE-2026-18347 is an authorization bypass vulnerability in the Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress, affecting all versions up to and including 6.1.1. It allows authenticated users to perform unauthorized actions due to improper authorization checks. Updating to the patched version is recommended.
Azərbaycanca: CVE-2026-18347, WordPress üçün Kirki – Freeform Page Builder, Website Builder & Customizer plaginində avtorizasiya bypass zəifliyidir. Bu zəiflik 6.1.1 daxil olmaqla bütün versiyalara təsir edir və autentifikasiya olunmuş istifadəçilərə icazəsiz əməliyyatlar aparmağa imkan verir. Plaginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin is affected by CVE-2026-18347, and what versions are vulnerable?
This vulnerability affects the Kirki – Freeform Page Builder, Website Builder & Customizer plugin. All versions up to and including 6.1.1 are vulnerable.
What does CVE-2026-18347 allow an authenticated user to do?
Due to improper authorization checks, the vulnerability allows an authenticated user to perform unauthorized actions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.