CVE-2026-84224

CVE-2026-84224 published: The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell ...

View full NVD advisory → ← Back to CVE watch