Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Jagadesh Achanta

#50823of 56,330
5.3Total CVSS
Vulnerabilities · 1
PT-2026-54939
5.3
2026-07-02
WordPress · Kirki · CVE-2026-12122
**Name of the Vulnerable Software and Affected Versions** Kirki – Freeform Page Builder, Website Builder & Customizer versions prior to 6.0.12 **Description** An issue exists that allows unauthenticated attackers to extract full builder metadata and rendered HTML of any `kirki symbol` post, including unpublished drafts. This is achieved by supplying a sequential WordPress post ID to the `get single symbol` function. **Recommendations** Update the plugin to version 6.0.12 or later.