CVE

CVE-2026-12720 — Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12720 Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.13 Deserialization of Untrusted Data Unknown < 6.0.13 6.0.13 2026-07-31

CVE-2026-12720

The Kirki WordPress plugin versions prior to 6.0.13 are vulnerable to PHP Object Injection due to insufficient restrictions on instantiated classes during deserialization of user-stored data. An attacker can exploit this by injecting malicious objects, which could result in remote code execution if the necessary conditions are met, such as specific plugins or outdated WordPress versions being present.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.