Security Advisory

CVE-2026-13147

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-20 06:00:04
Last updated 2026-07-20 13:13:37
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).