Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-57724: Kirki Themeum Kirki: Untrusted Data Causes Object Injection
CVE-2026-57724
CVE-2026-57724
Summary
Kirki, a plugin used in WordPress themes, has a vulnerability that allows attackers to inject malicious objects. This could potentially lead to unauthorized access or data tampering. Update Kirki to the latest version to fix this issue.
What to do
- Update themeum kirki to version 6.0.13.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| themeum | kirki |
<= 6.0.12 Fix: upgrade to 6.0.13
|
Original title
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
Original description
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
nvd CVSS3.1
9.8
Vulnerability type
CWE-502
Deserialization of Untrusted Data
Published: 13 Jul 2026 · Updated: 20 Jul 2026 · First seen: 13 Jul 2026