CVE

CVE-2026-12723 — Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12723 Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.12 Missing Authorization Unknown < 6.0.12 6.0.12 2026-06-29

CVE-2026-12723

The Kirki WordPress plugin versions prior to 6.0.12 lacks proper authorization checks for certain REST API endpoints, enabling unauthorized users to modify any existing comments and post pre-approved comments in another user's name without undergoing moderation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.