Frequency
3
occurrences
First Seen
August 2, 2026
Last Seen
August 2, 2026
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—
Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
The Kirki WordPress plugin prior to version 6.0.13 has a critical vulnerability (CVE-2026-12720) that allows unauthenticated users to store malicious serialized objects. This leads to PHP Object Injection when an administrator reviews the stored data, potentially enabling remote code execution if a...
Public Exploits
Checking GitHub for proof-of-concept code…