CVE-2026-12720: CWE-502 Deserialization of Untrusted Data in Kirki
CVE-2026-12720 is a deserialization vulnerability in the Kirki WordPress plugin before version 6.0.13. It allows unauthenticated users to store serialized data without restrictions on which classes may be instantiated. When an administrator later reviews this data, it can trigger PHP Object Injection. If a suitable gadget chain exists on the site, this vulnerability could lead to remote code execution or other attacks.
AI Analysis
Technical Summary
The Kirki WordPress plugin versions prior to 6.0.13 do not restrict class instantiation during deserialization of data that unauthenticated users can store. This leads to PHP Object Injection vulnerabilities triggered upon administrator review of the stored data. Exploitation requires a suitable gadget chain present on the site, which may come from another Kirki plugin version or an outdated WordPress installation. The vulnerability is identified as CWE-502 and has a CVSS 3.1 score of 7.5, indicating high severity. No official patch or remediation level is currently documented.
Potential Impact
Successful exploitation can lead to high-impact consequences including remote code execution, complete compromise of confidentiality, integrity, and availability of the affected system. The attack vector is remote with high attack complexity and no privileges required, but user interaction (administrator reviewing data) is necessary.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the plugin's data storage and review functionality to trusted administrators only. Monitor for updates from the Kirki plugin maintainers and apply any official patches promptly.
CVE-2026-12720: CWE-502 Deserialization of Untrusted Data in Kirki
Description
CVE-2026-12720 is a deserialization vulnerability in the Kirki WordPress plugin before version 6.0.13. It allows unauthenticated users to store serialized data without restrictions on which classes may be instantiated. When an administrator later reviews this data, it can trigger PHP Object Injection. If a suitable gadget chain exists on the site, this vulnerability could lead to remote code execution or other attacks.
CVSS v3.1
Score 7.5high
Affected software
Kirki
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Kirki WordPress plugin versions prior to 6.0.13 do not restrict class instantiation during deserialization of data that unauthenticated users can store. This leads to PHP Object Injection vulnerabilities triggered upon administrator review of the stored data. Exploitation requires a suitable gadget chain present on the site, which may come from another Kirki plugin version or an outdated WordPress installation. The vulnerability is identified as CWE-502 and has a CVSS 3.1 score of 7.5, indicating high severity. No official patch or remediation level is currently documented.
Potential Impact
Successful exploitation can lead to high-impact consequences including remote code execution, complete compromise of confidentiality, integrity, and availability of the affected system. The attack vector is remote with high attack complexity and no privileges required, but user interaction (administrator reviewing data) is necessary.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the plugin's data storage and review functionality to trusted administrators only. Monitor for updates from the Kirki plugin maintainers and apply any official patches promptly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-06-19T13:02:01.867Z
- State
- PUBLISHED
Threat ID: 6a6c42b49c2644c7f86e8537
Added to database: 07/31/2026, 06:37:40 UTC
Last enriched: 08/07/2026, 14:44:25 UTC
Last updated: 09/12/2026, 22:01:31 UTC
Views: 62
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.