The Kirki WordPress plugin before version 6.2.3 does not properly validate files in user-uploaded archives and does not remove unwanted files after extraction, allowing users with the Editor role to upload arbitrary files to a web-accessible directory. This could lead to Stored XSS and potentially RCE on certain server configurations. The vulnerability is particularly concerning for organizations using th [truncated]
The Kirki WordPress plugin before version 6.0.13 is vulnerable to SQL injection attacks due to improper sanitization and escaping of user-input values. This vulnerability allows unauthenticated attackers to perform malicious SQL queries, potentially leading to unauthorized data access or modification. Administrators and users of the Kirki WordPress plugin should be aware of this vulnerability and take nec [truncated]
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection. This vulnerability can be triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site, this could be leveraged to perform a variety of attacks, such as remote code ex [truncated]
The Kirki WordPress plugin before 6.0.12 has an HTML injection vulnerability. The plugin does not sanitize or escape email subject and body values supplied in a request before including them in the password-reset email it sends as HTML. This allows unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing. Affected users should be aware [truncated]
The Kirki WordPress plugin before 6.0.12 has a vulnerability allowing unauthenticated users to overwrite existing comments and create pre-approved comments under a spoofed identity, bypassing comment moderation. This issue affects users of the Kirki WordPress plugin, especially those with comment moderation enabled. The vulnerability class is related to insufficient authorization checks on REST routes. Th [truncated]