CVE-2026-12721: Unknown Kirki

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

Affected products

  • Unknown Kirki: before 6.0.13 (fixed in 6.0.13)

Published 2026-07-31. Last modified 2026-08-26.