The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 05 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open. | |
| Title | Kirki 6.0.0 - 6.2.5 - Authenticated Collaboration Comment Status Modification via IDOR | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-05T06:00:08.348Z
Reserved: 2026-09-01T11:50:36.164Z
Link: CVE-2026-84225
No data.
Status : Received
Published: 2026-09-05T07:17:13.760
Modified: 2026-09-05T07:17:13.760
Link: CVE-2026-84225
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.