CyberRota
Back to database

CVE-2026-8096

MEDIUM · CVSS 6.5 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published: 2026-05-19 · Last synced: 2026-06-17

CyberRota Analysis

Detaylı analiz gerekiyor.

CVE
CVE-2026-8096
Severity
MEDIUM
CVSS
6.5
EPSS
0.35%
WordPress

Original NVD Description

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to view all Kirki frontend forms and read stored visitor form submission data, including contact details, messages, and any other visitor-provided information submitted through site forms.