Record summary

CVE-2026-13147 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 20, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Kirki

Default status: unaffected

CVE ListBefore 6.0.12affected

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Kirki < 6.0.12 - Server-Side Request ForgeryCVSS 5.3

Kirki WordPress plugin < 6.0.12 contains a server-side request forgery caused by lack of URL validation, letting unauthenticated attackers make the site issue HTTP requests to arbitrary hosts, exploit requires no authentication.

Impact

Unauthenticated attackers can make the server send HTTP requests to arbitrary hosts, potentially leading to internal network access or data exposure.

Remediation

Update to version 6.0.12 or later.

WeaknessesCWE-918
Authors0x_Akoko
Template tagscvecve2026wordpresswp-pluginwpkirkissrfoast
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Shodan: http.html:"/wp-content/plugins/kirki/"
FOFA: body="/wp-content/plugins/kirki/"

Source: ProjectDiscovery

References

2