VYPR

Kirki

by WordPress

Source repositories

CVEs (25)

  • CVE-2026-57724CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

  • CVE-2026-57680MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.

  • CVE-2026-12472MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…

  • CVE-2026-12122MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.00

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.11 via the get_single_symbol. This makes it possible for unauthenticated attackers to extract the full…

  • CVE-2026-57627MedJun 26, 2026
    risk 0.00cvss 4.9epss 0.00

    Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.

Page 2 of 2