WordPress · Kirki · CVE-2026-12724
**Name of the Vulnerable Software and Affected Versions**
Kirki WordPress plugin versions prior to 6.0.12
**Description**
Unauthenticated users can inject arbitrary HTML into password-reset emails sent to registered users. This occurs because the plugin fails to sanitize or escape the email subject and body values provided in a request before including them in the HTML message, which could facilitate phishing attacks.
**Recommendations**
Update Kirki WordPress plugin to version 6.0.12 or later.