cleantalk
Vulnerabilities and Security Researches

Kirki Customizer Framework, CVE-2026-12723

CVE, Research URL

CVE-2026-12723

Published on
Jul 20, 2026
Research Description
The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment moderation.
Affected versions
max 6.0.12.
Status
vulnerable