CVE-2026-13147
The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated a
CVSS
9.1
Crítico
EPSS
0.1%
p3
KEV
—
Exploit Today
1
0-100
Publicado: 20 jul 2026 · Última mod.: 20 jul 2026
Sin historial EPSS suficiente todavía.
The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).
Sin CVEs relacionados por CWE o producto.