SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77754

MEDIUM · CVSS 5.3 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Kirki WordPress plugin prior to version 6.0.14 is vulnerable due to a lack of capability checks on certain public AJAX endpoints, enabling unauthenticated users to access sensitive information such as registered users' email addresses and non-public content. This exposure could lead to privacy breaches and unauthorized data access. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2026-77754
Severity
MEDIUM
CVSS
5.3
EPSS
0.27%
WordPress

Original NVD Description

The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJAX actions, allowing unauthenticated users to retrieve the email addresses of registered users and comment authors, as well as non-public page content and settings.