---
id: CVE-2026-84224
title: >-
  The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it
  is given before fetching it, allowing users with editor-level access and above
  to make the site issue requests to internal services that are not otherwise
  rea…
summary: >-
  The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it
  is given before fetching it, allowing users with editor-level access and above
  to make the site issue requests to internal services that are not otherwise
  rea…
severity: medium
cvss: 4.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N'
cwe:
  - CWE-918
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T15:17:17.390'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84224'
references:
  - url: 'https://wpscan.com/vulnerability/6a2455dd-8da9-4c7e-a249-3c694cf2983e/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00179
epssPercentile: 0.06843
ingestedAt: '2026-10-09T09:31:01.010Z'
---

## Overview

The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
