Junglewise Threat Intelligence

CVE-2026-12122: Themeum Kirki information exposure in get_single_symbol

CVE-2026-12122 · Severity: medium · CVSS 5.3 · Published 2026-07-02

Vendors: Themeum.

Executive brief

The Kirki plugin for WordPress, which is used to build and customize website pages, contains a security flaw that allows unauthorized individuals to view private content. An attacker can access draft posts and internal design data that were not intended for public viewing. This could lead to the exposure of sensitive business information or upcoming website changes before they are officially launched.

Technical details

The Kirki plugin for WordPress is vulnerable to sensitive information exposure due to missing authorization checks in the 'get_single_symbol' AJAX function. The vulnerability exists in all versions up to and including 6.0.11. An unauthenticated remote attacker can exploit this by sending requests with sequential WordPress post IDs to the vulnerable endpoint. Successful exploitation allows the attacker to retrieve the full builder metadata and rendered HTML of 'kirki_symbol' posts, including those in draft status that have not been published. The issue is classified under CWE-862 (Missing Authorization).

Affected products

  • Themeum Kirki – Freeform Page Builder, Website Builder & Customizer up to, and including, 6.0.11

Timeline

  • 2026-07-02: disclosed: CVE published by Wordfence
  • 2026-07-02: advisory: NVD record published

References