CyberRota Analysis
AI-GeneratedThe Kirki WordPress plugin prior to version 6.0.12 is vulnerable due to insufficient sanitization of email subject and body values in password-reset emails, enabling unauthenticated users to inject arbitrary HTML. This flaw poses a risk of phishing attacks targeting registered users through malicious content in the emails. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this security risk.
Original NVD Description
The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing.