Critical Vulnerability in Kirki WordPress Plugin Exposes Sites to Remote Code Execution
Article Content
- •CVE-2026-12720 affects Kirki WordPress plugin versions before 6.0.13.
- •The vulnerability allows PHP Object Injection, leading to potential remote code execution.
- •No confirmed exploits have been reported, but immediate updates are recommended.
The Kirki WordPress plugin prior to version 6.0.13 has a critical vulnerability (CVE-2026-12720) that allows unauthenticated users to store malicious serialized objects. This leads to PHP Object Injection when an administrator reviews the stored data, potentially enabling remote code execution if a suitable gadget chain exists. The vulnerability affects any WordPress site using the outdated Kirki plugin or older WordPress versions. Currently, there are no known public proof-of-concept exploits or confirmed instances of exploitation. Administrators are advised to update to version 6.0.13 or later and restrict access to trusted users. The CVSS score for this vulnerability is 7.5, indicating a high severity level. The vulnerability was officially published on July 31, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-12720 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…