CVE-2026-12721
Kirki
The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
- CVSS
- 8.6
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.31