CVE-2026-12720

CVE-2026-12720: Kirki < 6.0.13 - Unauthenticated PHP Object Injection

Vendor Unknown
Product Kirki
Published July 31, 2026
Last update July 31, 2026

CVSS base score

What the vulnerability does

01Description

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress version), this could be leveraged to perform a variety of attacks, such as remote code execution.

Key dates

02Disclosure timeline

July 31, 2026 CVE published
July 31, 2026 Record updated