CVE-2026-13147: Kirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apis
Published Jul 20, 2026
·Updated
The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).
Affected Software
1 affected component
WordPress Kirki<6.0.12
Event History
Jul 20, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-13147?
CVE-2026-13147 has a risk score of 54, indicating a medium level of severity.
2
How do I fix CVE-2026-13147?
To fix CVE-2026-13147, update the Kirki WordPress plugin to version 6.0.12 or later.
3
What type of vulnerability is CVE-2026-13147?
CVE-2026-13147 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
4
Who is affected by CVE-2026-13147?
Any WordPress site using Kirki versions prior to 6.0.12 is affected by CVE-2026-13147.
5
What can attackers do with CVE-2026-13147?
Attackers can use CVE-2026-13147 to make the site issue HTTP requests to arbitrary hosts without authentication.