SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-12724

MEDIUM · CVSS 4.3 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The Kirki WordPress plugin prior to version 6.0.12 is vulnerable due to insufficient sanitization of email subject and body values in password-reset emails, enabling unauthenticated users to inject arbitrary HTML. This flaw poses a risk of phishing attacks targeting registered users through malicious content in the emails. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this security risk.

CVE
CVE-2026-12724
Severity
MEDIUM
CVSS
4.3
EPSS
0.10%
WordPress

Original NVD Description

The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing.