Feed/CVE-2026-13147
CVE-2026-13147CRITICALCVSS 9.1

CVE-2026-13147

Published Jul 20, 2026·Updated Jul 20, 2026

NVD Description

The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free