A critical vulnerability has been reported in the Kirki plugin for WordPress that could allow an unauthenticated remote attacker to take over user accounts, including administrator accounts, on the targeted system.
Target Audience:
WordPress website owners, administrators, developers, and hosting providers using the Kirki plugin.
Risk Assessment:
Very high risk of account takeover, privilege escalation, unauthorized administrative access, and complete website compromise.
Impact Assessment:
Potential impact on confidentiality, integrity, and availability of the system.
The information provided herein is on "as is" basis, without warranty of any kind.