CVE-2026-12723 - Kirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderation Bypass via Component Library
CVE ID :CVE-2026-12723
Published : July 20, 2026, 7:16 a.m. | 3 hours, 32 minutes ago
Description :The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment moderation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 20, 2026, 7:16 a.m. | 3 hours, 32 minutes ago
Description :The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment moderation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...