Critical Vulnerability in Kirki WordPress Plugin Exposes Sites to Remote Code Execution
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Kirki WordPress plugin prior to version 6.0.13 has a critical vulnerability (CVE-2026-12720) that allows unauthenticated users to store malicious serialized objects. This leads to PHP Object Injection when an administrator reviews the stored data, potentially enabling remote code execution if a suitable gadget chain exists. The vulnerability affects any WordPress site using the outdated Kirki plugin or older WordPress versions. Currently, there are no known public proof-of-concept exploits or confirmed instances of exploitation. Administrators are advised to update to version 6.0.13 or later and restrict access to trusted users. The CVSS score for this vulnerability is 7.5, indicating a high severity level. The vulnerability was officially published on July 31, 2026.
Key Points: • CVE-2026-12720 affects Kirki WordPress plugin versions before 6.0.13. • The vulnerability allows PHP Object Injection, leading to potential remote code execution. • No confirmed exploits have been reported, but immediate updates are recommended.