Injection Vulnerability in Kirki WordPress Plugin Affects Unauthorized Users
CVE-2026-12724
Key Information:
Badges
What is CVE-2026-12724?
The Kirki WordPress plugin prior to version 6.0.12 is vulnerable due to inadequate sanitization and escaping of the email subject and body inputs. This flaw enables unauthorized users to inject arbitrary HTML code into the password-reset emails sent to registered users, thereby exposing them to potential phishing attacks. It's critical for WordPress developers and site administrators to update to the latest version to mitigate this risk and protect user data.
Affected Version(s)
Kirki 0 < 6.0.12
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved