CVE-2026-57724: WordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerability
Published Jul 13, 2026
·Updated
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
Affected Software
1 affected component
kirki<=6.0.12
Event History
Jul 13, 2026
CVE Published
via MITRE·08:41 AM
Data Sourced
via MITRE·08:41 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57724?
CVE-2026-57724 has a critical severity rating of 9.8.
2
What type of vulnerability is CVE-2026-57724?
CVE-2026-57724 is a PHP Object Injection vulnerability due to the deserialization of untrusted data.
3
How do I fix CVE-2026-57724?
To fix CVE-2026-57724, update the WordPress Kirki plugin to version 6.0.13 or later.
4
What versions of Kirki are affected by CVE-2026-57724?
CVE-2026-57724 affects all versions of the Kirki plugin up to and including 6.0.12.
5
What are the potential impacts of CVE-2026-57724?
Exploitation of CVE-2026-57724 can lead to remote code execution due to object injection.