Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-84220— Kirki < 6.3.2 - Unauthenticated Arbitrary Shortcode Execution via Comments Collection

Quick assessment

Affected
Unknown Kirki
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kirki WordPress 插件在 6.3.2 版本之前存在以下安全漏洞: 1. 未过滤短代码执行:在渲染评论内容时,插件未对嵌入评论中的短代码进行有效隔离或过滤,导致这些短代码被执行。这允许未认证用户运行站点中注册的所有短代码。 2. 忽略审核状态显示评论:无论评论是否处于待审核状态,插件均会直接将其展示。该行为可能导致敏感信息(如页面上私有自定义字段的内容)被未授权用户读取。 影响: 攻击者可通过提交未审核评论,利用漏洞执行任意短代码并窃取页面私有自定义字段数据,从而造成信息泄露或潜在的网站功能滥用。 修复

CVSS 4.8 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84220

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kirki < 6.3.2 - Unauthenticated Arbitrary Shortcode Execution via Comments Collection
Source: CVE Program / CVE List V5
Vulnerability Description
The Kirki WordPress plugin before 6.3.2 does not prevent shortcodes held in comments from being executed when it renders them, and displays comments regardless of their moderation status, allowing unauthenticated visitors to run shortcodes registered on the site and to read private custom fields of the page being viewed.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Kirki 0 ~ 6.3.2 -

II. Public POCs for CVE-2026-84220

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84220

请登录查看更多情报信息。

Other References for CVE-2026-84220 (1)

Same Patch Batch · Unknown · 2026-10-09 · 16 CVEs total

CVE-2026-89235 6.8 MEDIUM Testimonials by BestWebSoft 1.0.5 - 1.0.8 - Unauthenticated SQLi via 'offset' Parameter
CVE-2026-86851 6.5 MEDIUM Livees Checkout 6.8 - 7.0.2 - Unauthenticated Order Status Change, Order Note Injection &
CVE-2026-103329 5.3 MEDIUM Super Payments < 1.43.1 - Unauthenticated Payment Confirmation Forgery via Webhook Signatu
CVE-2026-87846 5.3 MEDIUM Shipping for Nova Poshta 1.18.7 - 1.19.8 - Unauthenticated Order Shipment Record Deletion
CVE-2026-85348 4.3 MEDIUM GDPR Data Request Form 1.5 - 1.7.1 - DPO Email Update via CSRF
CVE-2026-84224 4.1 MEDIUM Kirki < 6.3.2 - Editor+ Blind SSRF via Remote Template URL
CVE-2026-106095 Code Snippets < 3.10.0 - Admin+ Network-Scoped Snippet Activation and Deactivation via upd
CVE-2026-106097 Code Snippets < 3.10.0 - Admin+ SQLi in Migration Importers Leading to Network-Wide Creden
CVE-2026-93548 FooSales < 1.43.3 - Subscriber+ Privilege Escalation via User Impersonation
CVE-2026-87841 UnitechPay <= 1.0.6.3 - Unauthenticated Order Payment Bypass via Unsigned Webhook
CVE-2026-92990 SendPress <= 1.26.1.20 - Unauthenticated Newsletter Sending Log Disclosure via Hardcoded T
CVE-2026-88931 Social Web Suite <= 4.1.12 - Unauthenticated Arbitrary Plugin Settings Update
CVE-2026-86850 SKU Error Fixer for WooCommerce <= 1.0 - Unauthenticated Orphaned Product Variation Deleti
CVE-2025-15700 AWP Classifieds < 4.4.9 - Admin+ Arbitrary File Upload via ZIP Import
CVE-2026-92989 SendPress Newsletters <= 1.26.1.20 - Subscriber+ Mailing List Sync and Newsletter Queueing

IV. Related Vulnerabilities

V. Comments for CVE-2026-84220

No comments yet


Leave a comment