What is CVE-2026-12721?
The Kirki WordPress plugin before version 6.0.13 fails to properly sanitise and escape a value taken from the request before using it in an SQL statement, allowing unauthenticated attackers to perform SQL injection attacks. This vulnerability could be exploited to steal or manipulate the site's database. Updating the plugin to the latest version is recommended.
Azərbaycanca: Kirki WordPress plaqini 6.0.13-dən əvvəlki versiyalarda sorğudan alınan dəyəri SQL sorğusunda istifadə etməzdən əvvəl düzgün təmizləmir, bu isə autentifikasiya olunmamış hücumçulara SQL injection hücumları həyata keçirməyə imkan verir. Bu zəiflik saytın verilənlər bazasını oğurlamaq və ya manipulyasiya etmək üçün istifadə oluna bilər. Plaqinin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ1
What is the CVE-2026-12721 vulnerability in the Kirki WordPress plugin?
It is an SQL injection vulnerability that allows unauthenticated attackers to perform attacks because the plugin fails to properly sanitise and escape a value from the request before using it in an SQL statement, potentially leading to database theft or manipulation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.