CVE-2026-12720 | Kirki Plugin up to 6.0.12 on WordPress deserialization

SecurityVulns

A vulnerability was found in Kirki Plugin up to 6.0.12 on WordPress. It has been declared as problematic. The affected element is an unknown function. Executing a manipulation can lead to deserialization.

This vulnerability is handled as CVE-2026-12720. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More