SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-12723

MEDIUM · CVSS 5.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The Kirki WordPress plugin prior to version 6.0.12 is vulnerable due to a lack of authorization checks on a REST route, enabling unauthenticated users to overwrite existing comments and create new ones under a spoofed identity, effectively bypassing comment moderation. This could lead to content manipulation and potential reputational damage for affected sites. WordPress site administrators using the Kirki plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-12723
Severity
MEDIUM
CVSS
5.3
EPSS
0.20%
WordPress

Original NVD Description

The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment moderation.