CVE-2026-13147
EUVD-2026-4588920.07.2026, 07:16
The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.