CVE-2026-16747 carries a CVSS 3.1 base score of 6.5 against Kirki, a WordPress Customizer framework plugin, before version 6.2.1. NVD classifies it as CWE-74 (Injection). VulnCheck’s KEV feed reports the CVE as exploited, dated August 24, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-16747 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
Note on vendor attribution: our source data’s structured vendor field for this record does not match the plugin NVD’s own description names, and we could not independently corroborate it, so we omit a vendor-company attribution here and report only what NVD’s description text states about the plugin itself.
What the flaw is
Per NVD, Kirki before 6.2.1 fails to properly authorize its front-end form-submission REST routes, and passes attacker-controlled input through shortcode execution. That combination allows an unauthenticated user to run any shortcode registered on the site. On a default WordPress install, NVD states this leads to disclosure of the site administrator’s email address and lets an attacker relay mail to an arbitrary recipient from the victim’s own domain.
Evidence and confidence
- Medium confidence — the CVSS 6.5 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N), the CWE-74 classification, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by a WPScan vulnerability database entry cited in NVD’s own reference list. The exploitation report traces to VulnCheck KEV alone. - Moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.0022, a 12.6th percentile score as of our ingestion.
No field is in conflict between our two sources. Our source data does not carry a fixed-version field beyond NVD’s statement that the flaw affects versions before 6.2.1.
Why this matters
An unauthenticated attacker being able to trigger arbitrary registered shortcodes is a broader problem than the specific mail-relay impact NVD describes as the default-install consequence — the actual impact on any given site depends on which shortcodes other installed plugins and themes have registered, some of which may do far more than send email. The confirmed mail-relay abuse alone is enough to warrant treating this as a spam/phishing-infrastructure risk: an attacker can use the victim’s own domain reputation to relay messages to a recipient of their choosing.
Frequently Asked Questions
What is CVE-2026-16747? A CVSS 6.5 injection vulnerability (CWE-74) in the Kirki WordPress Customizer plugin before version 6.2.1, allowing unauthenticated shortcode execution via improperly authorized front-end form-submission REST routes.
Is CVE-2026-16747 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 24, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this? No. NVD’s description confirms this is exploitable by an unauthenticated user.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? Kirki 6.2.1 and later, per NVD’s description.
Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2026-16747, corroborated by WPScan’s vulnerability database entry. Exploitation status and the August 24, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.