PatchSiren

Kirki CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Kirki CVE published 2026-07-20

CVE-2026-12724

The Kirki WordPress plugin before 6.0.12 has an HTML injection vulnerability. The plugin does not sanitize or escape email subject and body values supplied in a request before including them in the password-reset email it sends as HTML. This allows unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing. Affected users should be aware [truncated]

Review Kirki CVE published 2026-07-20

CVE-2026-12723

The Kirki WordPress plugin before 6.0.12 has a vulnerability allowing unauthenticated users to overwrite existing comments and create pre-approved comments under a spoofed identity, bypassing comment moderation. This issue affects users of the Kirki WordPress plugin, especially those with comment moderation enabled. The vulnerability class is related to insufficient authorization checks on REST routes. Th [truncated]