---
id: CVE-2026-18335
title: >-
  The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for
  WordPress is vulnerable to Blind Server-Side Request Forgery in all versions
  up to, and including, 6.2.0 via the 'kirki_data' Parameter
summary: >-
  The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for
  WordPress is vulnerable to Blind Server-Side Request Forgery in all versions
  up to, and including, 6.2.0 via the 'kirki_data' Parameter. This makes it
  possible fo…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-918
vendor: themeum
product: 'Kirki – Freeform Page Builder, Website Builder & Customizer'
affected:
  - kirki_freeform_page_builder_website_builder_customizer <= 6.2.0
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T16:17:07.287'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18335'
references:
  - url: 'https://plugins.trac.wordpress.org/changeset/3636487/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/461be8a5-bf72-4028-88e6-bf6544120ac6?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T09:40:50.748Z'
---

## Overview

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 6.2.0 via the 'kirki_data' Parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
