CVE · Critical

CVE-2026-57724 — Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-57724 Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.13 Critical 9.8 < 6.0.13 6.0.13 2026-07-06

CVE-2026-57724

The Kirki plugin for WordPress contains a vulnerability that allows unauthenticated attackers to inject malicious PHP objects through deserialization of untrusted input in versions up to 6.0.12. This flaw can be exploited without any additional plugins or themes being present, but if a specific chain of vulnerabilities is also installed on the system, it could grant the attacker more severe privileges, including deleting files and accessing sensitive data.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.