CVE · Medium

CVE-2026-12472 — Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12472 Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.12 Missing Authorization Medium 5.3 < 6.0.12 6.0.12 2026-07-01

CVE-2026-12472

An authorization flaw in Kirki plugin versions up to 6.0.11 allows unauthorized users to send malicious emails from a WordPress site's mail server. This is due to inadequate verification of user permissions, enabling attackers to craft phishing messages with embedded valid password reset links. The vulnerability stems from the plugin's failure to properly sanitize email content and subject lines.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.