CVE-2026-12720

HIGH

Kirki < 6.0.13 - Unauthenticated PHP Object Injection

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-12720. PoCs published by webshellseo8.

AI-analyzed exploit summary This repository contains a placeholder script for CVE-2026-12720, a PHP Object Injection vulnerability in the Kirki WordPress Plugin (< 6.0.13). The script simulates an attack with a non-functional payload and lacks a real gadget chain or exploit code, serving only as an educational template.

Description

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress version), this could be leveraged to perform a variety of attacks, such as remote code execution.

Exploits (1)

github STUB
by webshellseo8 · pythonpoc
https://github.com/webshellseo8/CVE-2026-12720-Proof-of-Concept

This repository contains a placeholder script for CVE-2026-12720, a PHP Object Injection vulnerability in the Kirki WordPress Plugin (< 6.0.13). The script simulates an attack with a non-functional payload and lacks a real gadget chain or exploit code, serving only as an educational template.

Classification
Stub 95%
Attack Type
Deserialization
Complexity
Complex
Reliability
Theoretical
Target: Kirki WordPress Plugin < 6.0.13
No auth needed
Prerequisites: Unauthenticated access to store serialized data · Administrator interaction to trigger deserialization · A suitable gadget chain on the target server
mistral-large-3 · analyzed Aug 04, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/22f5af1c-972e-4e31-9afa-bf50ac278c66/

Scores

CVSS v3 7.5
EPSS 0.0030
EPSS Percentile 22.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-502
Status published
Products (1)
None/Kirki < 6.0.13
Published Jul 31, 2026
Tracked Since Jul 31, 2026