CVE-2026-12723
Deferred Deferred - Pending Action

Kirki Plugin Comment Spoofing and Moderation Bypass

Vulnerability report for CVE-2026-12723, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: WPScan

Description

The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment moderation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kirki plugin to 6.0.12 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Kirki WordPress plugin before version 6.0.12 has a vulnerability where an unauthenticated user can exploit a missing authorization check in a REST route. This allows them to overwrite existing comments or create new pre-approved comments under a fake identity, bypassing comment moderation systems.

Detection Guidance

Check if the Kirki plugin version is below 6.0.12 by inspecting the WordPress admin panel or using commands like 'wp plugin list' in WP-CLI. Monitor for unauthorized comment modifications or new comments under spoofed identities.

Impact Analysis

An attacker could modify or delete comments on your WordPress site without permission, post fake comments under your name or others', or bypass moderation to spread misinformation or spam. This could damage your site's reputation or integrity.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by allowing unauthorized modification of comments, which may include sensitive user data. Unauthenticated attackers could alter or approve comments under fake identities, potentially violating data integrity and user consent requirements.

Mitigation Strategies

Update the Kirki plugin to version 6.0.12 or later immediately. If updating is not possible, consider disabling the plugin temporarily until a patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12723. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart