CVE-2026-18347

Kirki <= 6.1.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'context' Parameter

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.1.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to read arbitrary user metadata and sensitive user record fields — including email address, assigned roles, registration date, and any user_meta values — belonging to any WordPress user including administrators, by supplying a target user ID with a user-type context to the frontend collection endpoint.


We have discovered 3,091 live websites that are affected by CVE-2026-18347.

Run a Free Instant Scan




Affected Software

Product  Kirki Customizer Framework
Category Wordpress Plugins
Vulnerable Domains3,091 live websites (100% of Kirki Customizer Framework install base)
Vulnerable Versions
  • from 0 through 6.1.1
Vulnerable Versions Count19 versions ( 95% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Aug 16, 2026
  • Updated - Aug 17, 2026

Credits

  • Datist Pham (finder)

Website Distribution by Country

Number of websites using CVE-2026-18347
United States735 websites



Germany338 websites
France246 websites
Italy221 websites
Poland150 websites
GB113 websites
Spain100 websites
Russia85 websites
Netherlands71 websites
India60 websites

Website Distribution by TLD

Number of websites using CVE-2026-18347
.com1,411 websites
.de188 websites
.it129 websites
.pl110 websites
.fr93 websites
.org86 websites
.ru66 websites
.co.uk54 websites
.nl53 websites
.net47 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18347

Top websites that are affected by CVE-2026-18347. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States**,***
********.**.za South Africa***,***
********.nl Netherlands***,***
**********.be Belgium***,***
*******************.pl Poland***,***
**********.com China***,***
************************.org United States***,***
***********************.xn--p1ai Russia***,***
************.com Cyprus***,***
*********.com GB***,***
See full domain list

FAQ

CVE-2026-18347 is Missing Authorization in Kirki Customizer Framework
A total of 3,091 websites have been identified as vulnerable to CVE-2026-18347, based on global website indexing conducted by WebTechSurvey.
The Kirki Customizer Framework is affected by the CVE-2026-18347 vulnerability.
Kirki Customizer Framework versions up to and including 6.1.1 are vulnerable to CVE-2026-18347.

References