CVE-2026-13147: Kirki WordPress Plugin SSRF Allows Unauthenticated Internal Network Scanning
ID: 7f7b6d39-d39d-504e-8bcf-694936803676
STIX ID: report--7f7b6d39-d39d-504e-8bcf-694936803676
Feed Name: CosmicBytez Labs
A high-severity (CVSS 9.1) unauthenticated SSRF vulnerability (CVE-2026-13147) was found in the Kirki Customizer Framework WordPress plugin prior to version 6.0.12; attackers can force server-side HTTP requests to arbitrary hosts, enabling cloud metadata theft, internal network reconnaissance, and potential full server compromise. The report details attack scenarios, detection indicators, and recommends immediate plugin updates to 6.0.12 plus network- and WordPress-level mitigations (block metadata endpoints, enable IMDSv2, and filter internal IPs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
