Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the WordPress Kirki plugin to the latest available version (at least 6.3.2).
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 03 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 03 Oct 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1. | |
| Title | WordPress Kirki plugin <= 6.3.1 - Arbitrary Code Execution vulnerability | |
| Weaknesses | CWE-1284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-10-03T15:12:23.648Z
Reserved: 2026-09-30T00:15:58.644Z
Link: CVE-2026-103065
Updated: 2026-10-03T15:11:22.751Z
Status : Received
Published: 2026-10-03T15:16:35.300
Modified: 2026-10-03T16:16:32.670
Link: CVE-2026-103065
No data.
OpenCVE Enrichment
Updated: 2026-10-03T16:30:07Z