WordPress · Kirki · CVE-2026-13147
**Name of the Vulnerable Software and Affected Versions**
Kirki WordPress plugin versions prior to 6.0.12
**Description**
An issue exists where the software fails to validate a user-supplied URL before requesting it server-side. This allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF), a technique where the server is coerced into making HTTP requests to arbitrary hosts.
**Recommendations**
Update Kirki WordPress plugin to version 6.0.12 or later.