CyberRota Analysis
AI-GeneratedThe Kirki WordPress plugin prior to version 6.0.12 is vulnerable due to a lack of authorization checks on a REST route, enabling unauthenticated users to overwrite existing comments and create new ones under a spoofed identity, effectively bypassing comment moderation. This could lead to content manipulation and potential reputational damage for affected sites. WordPress site administrators using the Kirki plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment moderation.