Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-74 | |
| Metrics |
ssvc
|
Wed, 12 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticated users to run any shortcode registered on the site, which on a default install leads to disclosure of the site administrator's email address and an arbitrary-recipient mail relay from the victim's domain. | |
| Title | Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-12T12:12:18.556Z
Reserved: 2026-07-23T12:09:27.936Z
Link: CVE-2026-16747
Updated: 2026-08-12T12:12:03.949Z
Status : Received
Published: 2026-08-12T12:17:47.053
Modified: 2026-08-12T13:17:19.900
Link: CVE-2026-16747
No data.
OpenCVE Enrichment
No data.