The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0.14 via the 'context' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the full title, content, and excerpt of any WordPress post — including drafts, pending, privately published, password-protected, and trashed posts — regardless of author, by supplying an arbitrary post ID via the context parameter alongside an attacker-controlled block template.
Metrics
Affected Vendors & Products
References
History
Fri, 24 Jul 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themeum
Themeum kirki – Freeform Page Builder, Website Builder & Customizer Wordpress Wordpress wordpress |
|
| Vendors & Products |
Themeum
Themeum kirki – Freeform Page Builder, Website Builder & Customizer Wordpress Wordpress wordpress |
Fri, 24 Jul 2026 03:45:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-07-24T14:40:01.097Z
Reserved: 2026-06-26T20:12:35.429Z
Link: CVE-2026-13464
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T04:30:03Z