Kirki
by WordPress
Source repositories
CVEs (25)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-57724 | Cri | 0.00 | 9.8 | 0.00 | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12. | ||
| CVE-2026-57680 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions. | ||
| CVE-2026-12472 | Med | 0.00 | 5.3 | 0.00 | Jul 2, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes… | ||
| CVE-2026-12122 | Med | 0.00 | 5.3 | 0.00 | Jul 2, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.11 via the get_single_symbol. This makes it possible for unauthenticated attackers to extract the full… | ||
| CVE-2026-57627 | Med | 0.00 | 4.9 | 0.00 | Jun 26, 2026 | Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions. |
- risk 0.00cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.
- risk 0.00cvss 5.3epss 0.00
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…
- risk 0.00cvss 5.3epss 0.00
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.11 via the get_single_symbol. This makes it possible for unauthenticated attackers to extract the full…
- risk 0.00cvss 4.9epss 0.00
Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.
Page 2 of 2