CVE-2026-12720
HIGHKirki < 6.0.13 - Unauthenticated PHP Object Injection
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-12720. PoCs published by webshellseo8.
AI-analyzed exploit summary This repository contains a placeholder script for CVE-2026-12720, a PHP Object Injection vulnerability in the Kirki WordPress Plugin (< 6.0.13). The script simulates an attack with a non-functional payload and lacks a real gadget chain or exploit code, serving only as an educational template.
Description
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress version), this could be leveraged to perform a variety of attacks, such as remote code execution.
Exploits (1)
This repository contains a placeholder script for CVE-2026-12720, a PHP Object Injection vulnerability in the Kirki WordPress Plugin (< 6.0.13). The script simulates an attack with a non-functional payload and lacks a real gadget chain or exploit code, serving only as an educational template.
References (1)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H