Retour à la veille

CVE-2026-84222

Publié : 9 septembre 2026
Modifié : 9 septembre 2026
Lien officiel NVD

Description détaillée

The Kirki WordPress plugin before 6.3.0 does not check whether the requester is allowed to read a post before rendering and returning its page content, allowing unauthenticated users to retrieve the content of pages that are not publicly available, such as private, draft, pending and trashed ones.

Références et Patchs