Critical Vulnerability in Kirki WordPress Plugin Exposes Sites to Remote Code Execution

Critical Vulnerability in Kirki WordPress Plugin Exposes Sites to Remote Code Execution

First seen 2 Aug 2026, 08:52 UTC Feedlywww.incibe.esnvd.nist.govvulners.comdb.gcve.eu 90% similarity 67.5

Article Content

Browse articles
ThreatCluster

The Kirki WordPress plugin prior to version 6.0.13 has a critical vulnerability (CVE-2026-12720) that allows unauthenticated users to store malicious serialized objects. This leads to PHP Object Injection when an administrator reviews the stored data, potentially enabling remote code execution if a suitable gadget chain exists. The vulnerability affects any WordPress site using the outdated Kirki plugin or older WordPress versions. Currently, there are no known public proof-of-concept exploits or confirmed instances of exploitation. Administrators are advised to update to version 6.0.13 or later and restrict access to trusted users. The CVSS score for this vulnerability is 7.5, indicating a high severity level. The vulnerability was officially published on July 31, 2026.

Key Points: • CVE-2026-12720 affects Kirki WordPress plugin versions before 6.0.13. • The vulnerability allows PHP Object Injection, leading to potential remote code execution. • No confirmed exploits have been reported, but immediate updates are recommended.

ThreatCluster AI How this analysis works

Timeline

2026-07-31
CVE-2026-12720 published
The vulnerability in Kirki WordPress plugin was officially published, detailing the PHP Object Injection risk.
NVD
2026-08-02
Multiple advisories released
Advisories from Feedly, NVD, and INCIBE-CERT highlight the critical nature of CVE-2026-12720.
Feedly
2026-08-02
Recommendations issued for plugin update
Security experts recommend updating the Kirki plugin to version 6.0.13 or later to mitigate risks.
INCIBE-CERT

Community

Browse all →

Tracked Entities in This Story