Server-Side Request Forgery Vulnerability in Kirki WordPress Plugin by David E. Heddings
CVE-2026-13147
Key Information:
Badges
What is CVE-2026-13147?
The Kirki WordPress plugin prior to version 6.0.12 is susceptible to a sever-side request forgery (SSRF) vulnerability. This issue arises because the plugin does not adequately validate URLs provided by users, potentially allowing unauthenticated attackers to initiate HTTP requests to arbitrary servers from the affected website. Such exploitation may lead to unauthorized access to internal services or leakage of sensitive information. Website administrators are strongly advised to update to the latest version of the plugin to mitigate these risks.
Affected Version(s)
Kirki 0 < 6.0.12
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved