CyberRota Analysis
AI-GeneratedThe Kirki WordPress plugin prior to version 6.3.0 is vulnerable due to inadequate escaping of user-supplied identifiers in SQL queries, which allows users with editor-level access or higher to execute arbitrary SQL commands. This vulnerability can lead to unauthorized access to sensitive database information, including user credentials. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential data breaches.
Original NVD Description
The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.