CVE

CVE-2026-12724 — Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12724 Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.12 Insufficient Verification of Data Authenticity Unknown < 6.0.12 6.0.12 2026-06-29

CVE-2026-12724

The Kirki WordPress plugin versions prior to 6.0.12 fails to properly sanitize and escape email subject and body values, enabling unauthenticated attackers to inject arbitrary HTML content into password-reset emails sent to users. This vulnerability could allow for phishing attacks targeting registered users.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.