Vulnerability Description
The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.
CVSS Score
LOW
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-84225?
CVE-2026-84225 is a vulnerability with a CVSS score of 2.2 (LOW). The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-lev...
How severe is CVE-2026-84225?
CVE-2026-84225 has been rated LOW with a CVSS base score of 2.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-84225?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.