Skip to content
Critical Vulnerability in Kirki WordPress Plugin Exposes Sites to Remote Code Execution

Critical Vulnerability in Kirki WordPress Plugin Exposes Sites to Remote Code Execution

First seen 2 Aug 2026, 08:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 3, 2026 at 06:03 UTC
  • CVE-2026-12720 affects Kirki WordPress plugin versions before 6.0.13.
  • The vulnerability allows PHP Object Injection, leading to potential remote code execution.
  • No confirmed exploits have been reported, but immediate updates are recommended.

The Kirki WordPress plugin prior to version 6.0.13 has a critical vulnerability (CVE-2026-12720) that allows unauthenticated users to store malicious serialized objects. This leads to PHP Object Injection when an administrator reviews the stored data, potentially enabling remote code execution if a suitable gadget chain exists. The vulnerability affects any WordPress site using the outdated Kirki plugin or older WordPress versions. Currently, there are no known public proof-of-concept exploits or confirmed instances of exploitation. Administrators are advised to update to version 6.0.13 or later and restrict access to trusted users. The CVSS score for this vulnerability is 7.5, indicating a high severity level. The vulnerability was officially published on July 31, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 50d ago How this analysis works

Timeline

2026-07-31
CVE-2026-12720 published
The vulnerability in Kirki WordPress plugin was officially published, detailing the PHP Object Injection risk.
NVD
2026-08-02
Multiple advisories released
Advisories from Feedly, NVD, and INCIBE-CERT highlight the critical nature of CVE-2026-12720.
Feedly
2026-08-02
Recommendations issued for plugin update
Security experts recommend updating the Kirki plugin to version 6.0.13 or later to mitigate risks.
INCIBE-CERT

More articles in this cluster (5)

Following this threat?

Track CVE-2026-12720 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed