Authorization Bypass Vulnerability in Kirki Website Builder Plugin for WordPress
CVE-2026-12472

5.3MEDIUM

What is CVE-2026-12472?

The Kirki – Freeform Page Builder plugin for WordPress contains a vulnerability that allows unauthorized users to perform actions without proper verification. This flaw can be exploited by unauthenticated attackers to initiate arbitrary HTML-injected emails to any registered user on the site. The emails can include phishing messages with a genuine WordPress password-reset link, taking advantage of the site's own email server reputation. The vulnerability arises from inadequate sanitization of the email subject and body content, making it possible for attackers to craft deceptive messages that could lead to credential theft.

Affected Version(s)

Kirki – Freeform Page Builder, Website Builder & Customizer 0 <= 6.0.11

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Niv Kochan
Matan Bahar
.