The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticated users to run any shortcode registered on the site, which on a default install leads to disclosure of the site administrator's email address and an arbitrary-recipient mail relay from the victim's domain.
We have discovered 3,093 live websites that are affected by CVE-2026-16747.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 3,093 live websites (100% of Kirki Customizer Framework install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 20 versions ( 100% of all versions) |
| 737 websites | |
| 338 websites | |
| 246 websites | |
| 221 websites | |
| 150 websites | |
| 113 websites | |
| 100 websites | |
| 85 websites | |
| 71 websites | |
| 60 websites |
| .com | 1,413 websites |
| .de | 188 websites |
| .it | 129 websites |
| .pl | 110 websites |
| .fr | 93 websites |
| .org | 86 websites |
| .ru | 66 websites |
| .co.uk | 54 websites |
| .nl | 53 websites |
| .net | 47 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | **,*** | ||
| *******.com | **,*** | ||
| ********.**.za | ***,*** | ||
| ********.nl | ***,*** | ||
| **********.be | ***,*** | ||
| *******************.pl | ***,*** | ||
| **********.com | ***,*** | ||
| ************************.org | ***,*** | ||
| ***********************.xn--p1ai | ***,*** | ||
| ************.com | ***,*** |
FAQ