What is CVE-2026-12720?
CVE-2026-12720 is a PHP Object Injection vulnerability in the Kirki WordPress plugin before version 6.0.13, caused by a lack of class restriction during deserialization of data stored by unauthenticated users. The flaw is triggered when an administrator reviews the stored data, potentially leading to severe exploitation if a suitable gadget chain is present. Updating to the latest plugin version is strongly advised.
Azərbaycanca: CVE-2026-12720 Kirki WordPress plaginində (6.0.13-dən əvvəlki versiyalarda) autentifikasiya olunmamış istifadəçilərin saxladığı məlumatların deserializasiyası zamanı sinif instansiyasının məhdudlaşdırılmaması səbəbindən PHP Object Injection zəifliyidir. Bu boşluq, administrator saxlanılan məlumatları nəzərdən keçirərkən işə düşür və mövcud gadget chain ilə ciddi təhlükəsizlik riski yaradır. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Is authentication required to exploit CVE-2026-12720 in the Kirki WordPress plugin?
No, CVE-2026-12720 occurs during deserialization of data stored by unauthenticated users, so authentication is not required for the attack. However, the vulnerability is triggered when an administrator reviews the stored data.
What version of the Kirki plugin should be updated to mitigate CVE-2026-12720?
To mitigate CVE-2026-12720, it is recommended to update the Kirki WordPress plugin to version 6.0.13 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.