CVE Database /
CVE-2026-12721
CVE
CVE-2026-12721 — Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.13
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12721
|
Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.13 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Unknown
|
< 6.0.13
|
6.0.13 |
2026-07-14 |
—
|
CVE-2026-12721
The Kirki WordPress plugin versions prior to 6.0.13 is vulnerable to SQL injection due to insufficient sanitization of user input before its use in database queries, exposing unauthenticated users to potential attack vectors.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings