CVE-2026-84225 - CERT CVE
ID CVE-2026-84225
Sažetak The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.
Reference
CVSS
Base: 2.2
Impact: 1.4
Exploitability:0.7
Pristup
VektorSloženostAutentikacija
NETWORK HIGH HIGH
Impact
PovjerljivostCjelovitostDostupnost
NONE LOW NONE
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Zadnje važnije ažuriranje 06-09-2026 - 11:18
Objavljeno 05-09-2026 - 07:17