CVE-2026-12720

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress version), this could be leveraged to perform a variety of attacks, such as remote code execution.
Configurations

No configuration.

History

31 Jul 2026, 18:17

Type Values Removed Values Added
CWE CWE-502
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

31 Jul 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-31 07:16

Updated : 2026-07-31 18:17


NVD link : CVE-2026-12720

Mitre link : CVE-2026-12720

CVE.ORG link : CVE-2026-12720


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data