CVE intelligence

CVE-2026-84221

The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with edito

Published 2026-09-05 · CVSS

medium

NIST record