CVE Database /
CVE-2026-12720
CVE
CVE-2026-12720 — Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.13
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12720
|
Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.13 |
Deserialization of Untrusted Data |
Unknown
|
< 6.0.13
|
6.0.13 |
2026-07-31 |
—
|
CVE-2026-12720
The Kirki WordPress plugin versions prior to 6.0.13 are vulnerable to PHP Object Injection due to insufficient restrictions on instantiated classes during deserialization of user-stored data. An attacker can exploit this by injecting malicious objects, which could result in remote code execution if the necessary conditions are met, such as specific plugins or outdated WordPress versions being present.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings