The Kirki WordPress plugin before 6.0.12 has an HTML injection vulnerability. The plugin does not sanitize or escape email subject and body values supplied in a request before including them in the password-reset email it sends as HTML. This allows unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing. Affected users should be aware [truncated]
The Kirki WordPress plugin before 6.0.12 has a vulnerability allowing unauthenticated users to overwrite existing comments and create pre-approved comments under a spoofed identity, bypassing comment moderation. This issue affects users of the Kirki WordPress plugin, especially those with comment moderation enabled. The vulnerability class is related to insufficient authorization checks on REST routes. Th [truncated]