Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical security vulnerability in the Kirki WordPress plugin that could allow unauthorized individuals to take over user accounts. The issue stems from how the plugin handles password reset requests, potentially enabling attackers to redirect reset links to their own email addresses. The primary concern is to confirm if this plugin is in use and if so, assess any exposure.
- Unauthenticated users can reset any account password.
- Could lead to unauthorized access and control of websites.
- Confirm if this plugin is in use and assess exposure.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by initiating a password reset request for any user on a WordPress site running the Kirki plugin. By providing their own email address during the reset process, the attacker can intercept the password reset link and take over the target user's account. This could lead to unauthorized access and modification of website content or user data.
- No authentication is required to start.
- Password reset feature is the trigger.
- Risk of account takeover.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated attacker to take over any user account on a WordPress site using the Kirki plugin by sending a password reset link to their own email address. This is possible because the plugin improperly accepts an arbitrary email address during the password reset process.
- User account access.
- Password reset request manipulation.
- Unauthorized account control.
Operational Fix
Recommended remediation, mitigation, and detection steps
WordPress site owners and their security teams should address this critical privilege escalation vulnerability. The first practical step is to identify all WordPress sites utilizing the Kirki plugin, confirm their internet accessibility and business criticality, and then assign ownership for remediation planning.
- WordPress site owners should own the issue.
- Verify plugin use and email reset functionality.
- Plan and execute remediation per risk.