The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).
The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 91.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 91.00 |
VPI formula vpi-v1