CVE-2026-12723 PUBLISHED

Kirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderation Bypass via Component Library

Assigner: WPScan
Reserved: 19.06.2026 Published: 20.07.2026 Updated: 20.07.2026

The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment moderation.

Product Status

Vendor Unknown
Product Kirki
Versions Default: unaffected
  • affected from 0 to 6.0.12 (excl.)

Credits

  • Shivamani Vastrala finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE