CVE-2026-12724
Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password
CVSS Score
4.3
EPSS Score
0.1%
EPSS Percentile
1th
The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing.
| Vendor | unknown |
| Product | kirki |
| Published | Jul 20, 2026 |
| Last Updated | Jul 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown kirki
Be the first to know when new medium vulnerabilities affecting unknown kirki are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Kirki
0 < 6.0.12
References
Credits
Tarcísio Luchesi WPScan