CVE-2026-84224
MEDIUM
NVD
CVSS Score
4.1
Severity
MEDIUM
Published
Oct 09, 2026
Vendor
unknown
Description
The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response.