CVE-2026-13147
Kirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apis
Record summary
CVE-2026-13147 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.
Description
The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 20, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
KirkiDefault status: unaffected | CVE List | Before 6.0.12 | affected |
Nuclei templates
1ProjectDiscoveryHIGHWordPress Kirki < 6.0.12 - Server-Side Request ForgeryCVSS 5.3
Kirki WordPress plugin < 6.0.12 contains a server-side request forgery caused by lack of URL validation, letting unauthenticated attackers make the site issue HTTP requests to arbitrary hosts, exploit requires no authentication.
Impact
Unauthenticated attackers can make the server send HTTP requests to arbitrary hosts, potentially leading to internal network access or data exposure.
Remediation
Update to version 6.0.12 or later.
Source: ProjectDiscovery