CyberRota Analysis
AI-GeneratedThe Kirki WordPress plugin prior to version 6.0.12 is vulnerable to Server-Side Request Forgery (SSRF) due to inadequate validation of user-supplied URLs, enabling unauthenticated attackers to make the server issue HTTP requests to arbitrary hosts. This critical vulnerability could lead to data exfiltration or further exploitation of the server environment. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential risks.
Original NVD Description
The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).