Skip to content

Known CVE

WordPress Kirki < 6.0.12 - Server-Side Request Forgery

Kirki WordPress plugin < 6.0.12 contains a server-side request forgery caused by lack of URL validation, letting unauthenticated attackers make the site issue HTTP requests to arbitrary hosts, exploit requires no authentication.

CVE-2026-13147

High2026CVSS 5.3CWE-918

cve2026 · wordpress · wp-plugin · wp · kirki · ssrf · oast

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website