CVE-2026-12721: Unknown Kirki
High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.
The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
Affected products
- Unknown Kirki: before 6.0.13 (fixed in 6.0.13)
Published 2026-07-31. Last modified 2026-08-26.