logo

CVE-2026-13147: Kirki WordPress Plugin SSRF Allows Unauthenticated Internal Network Scanning

ID: 7f7b6d39-d39d-504e-8bcf-694936803676

STIX ID: report--7f7b6d39-d39d-504e-8bcf-694936803676

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

...
...

A high-severity (CVSS 9.1) unauthenticated SSRF vulnerability (CVE-2026-13147) was found in the Kirki Customizer Framework WordPress plugin prior to version 6.0.12; attackers can force server-side HTTP requests to arbitrary hosts, enabling cloud metadata theft, internal network reconnaissance, and potential full server compromise. The report details attack scenarios, detection indicators, and recommends immediate plugin updates to 6.0.12 plus network- and WordPress-level mitigations (block metadata endpoints, enable IMDSv2, and filter internal IPs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.