{"id":"CVE-2026-84225","title":"The Kirki  WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modi…","summary":"The Kirki  WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modi…","severity":"low","cvss":2.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-639"],"published":"2026-09-05","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:09:21.310","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84225","references":[{"url":"https://wpscan.com/vulnerability/9f83f0a2-7d77-49a2-a23a-03f787e2e356/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00232,"epssPercentile":0.12489,"ingestedAt":"2026-09-06T06:51:17.268Z","slug":"CVE-2026-84225","body":"## Overview\n\nThe Kirki  WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":12,"depthScoreParts":{"impact":12.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":8282,"id":"CVE-2026-84225","ts":1788919995808,"field":"cvss","old":null,"new":"2.2"},{"seq":8281,"id":"CVE-2026-84225","ts":1788919995808,"field":"severity","old":"none","new":"low"},{"seq":8091,"id":"CVE-2026-84225","ts":1788919281175,"field":"cvss","old":"2.2","new":null},{"seq":8090,"id":"CVE-2026-84225","ts":1788919281175,"field":"severity","old":"low","new":"none"},{"seq":7900,"id":"CVE-2026-84225","ts":1788916356986,"field":"cvss","old":null,"new":"2.2"},{"seq":7899,"id":"CVE-2026-84225","ts":1788916356986,"field":"severity","old":"none","new":"low"},{"seq":7709,"id":"CVE-2026-84225","ts":1788915298078,"field":"cvss","old":"2.2","new":null},{"seq":7708,"id":"CVE-2026-84225","ts":1788915298078,"field":"severity","old":"low","new":"none"},{"seq":7518,"id":"CVE-2026-84225","ts":1788912717531,"field":"cvss","old":null,"new":"2.2"},{"seq":7517,"id":"CVE-2026-84225","ts":1788912717531,"field":"severity","old":"none","new":"low"},{"seq":7327,"id":"CVE-2026-84225","ts":1788911331835,"field":"cvss","old":"2.2","new":null},{"seq":7326,"id":"CVE-2026-84225","ts":1788911331835,"field":"severity","old":"low","new":"none"},{"seq":7131,"id":"CVE-2026-84225","ts":1788909079153,"field":"cvss","old":null,"new":"2.2"},{"seq":7130,"id":"CVE-2026-84225","ts":1788909079153,"field":"severity","old":"none","new":"low"},{"seq":6943,"id":"CVE-2026-84225","ts":1788907391900,"field":"cvss","old":"2.2","new":null},{"seq":6942,"id":"CVE-2026-84225","ts":1788907391900,"field":"severity","old":"low","new":"none"},{"seq":6745,"id":"CVE-2026-84225","ts":1788905445078,"field":"cvss","old":null,"new":"2.2"},{"seq":6744,"id":"CVE-2026-84225","ts":1788905445078,"field":"severity","old":"none","new":"low"},{"seq":6563,"id":"CVE-2026-84225","ts":1788903460114,"field":"cvss","old":"2.2","new":null},{"seq":6562,"id":"CVE-2026-84225","ts":1788903460114,"field":"severity","old":"low","new":"none"},{"seq":6349,"id":"CVE-2026-84225","ts":1788901811234,"field":"cvss","old":null,"new":"2.2"},{"seq":6348,"id":"CVE-2026-84225","ts":1788901811234,"field":"severity","old":"none","new":"low"},{"seq":6179,"id":"CVE-2026-84225","ts":1788899562497,"field":"cvss","old":"2.2","new":null},{"seq":6178,"id":"CVE-2026-84225","ts":1788899562497,"field":"severity","old":"low","new":"none"},{"seq":6047,"id":"CVE-2026-84225","ts":1788898240542,"field":"cvss","old":null,"new":"2.2"},{"seq":6046,"id":"CVE-2026-84225","ts":1788898240542,"field":"severity","old":"none","new":"low"}]}