Junglewise Threat Intelligence

CVE-2026-12472: Kirki Freeform Page Builder authorization bypass in CompLibFormHandler

CVE-2026-12472 · Severity: medium · CVSS 5.3 · Published 2026-07-02

Vendors: Themeum.

Executive brief

A popular WordPress website builder plugin contains a security flaw that allows unauthorized individuals to send emails through your website's official mail server. Attackers can use this to send convincing phishing messages to your registered users, which may include legitimate password-reset links to trick them into compromising their accounts. Because these emails come from your own server, they are more likely to bypass spam filters and appear trustworthy to your customers.

Technical details

The Kirki plugin (versions up to 6.0.11) fails to implement proper authorization checks in its ComponentLibrary form handling logic, specifically within CompLibFormHandler.php. This missing authorization (CWE-862) allows unauthenticated remote attackers to trigger the wp_mail() function. The vulnerability is exacerbated by insufficient sanitization: the 'emailSubject' parameter only uses sanitize_text_field(), and 'emailBody' text items are concatenated raw without escaping. Attackers can inject arbitrary HTML and include 'chip' items that generate genuine WordPress password-reset links for targeted users, leveraging the site's SPF/DKIM reputation to ensure delivery.

Affected products

  • themeum Kirki – Freeform Page Builder, Website Builder & Customizer up to, and including, 6.0.11

Timeline

  • 2026-07-02: advisory: Published by Wordfence and NVD

References