Junglewise Threat Intelligence

CVE-2026-57627: Themeum Kirki SSRF in WordPress plugin

CVE-2026-57627 · Severity: medium · CVSS 4.9 · Published 2026-06-26

Technologies: Themeum Kirki. Vendors: Themeum.

Executive brief

Kirki, a popular WordPress framework used by developers to build custom themes, contains a security flaw that could allow users with basic 'Subscriber' accounts to make the server perform unauthorized web requests. An attacker could use this to probe internal network services or access sensitive information that is not intended to be public. This could lead to internal data exposure or be used as a stepping stone for further attacks on the hosting infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Kirki Customizer Framework plugin for WordPress (versions 6.0.11 and below). The flaw allows an authenticated attacker with Subscriber-level privileges to influence the destination of web requests made by the server. This is classified under CWE-918 and occurs because the application does not sufficiently validate user-supplied URLs before performing a request. An attacker can exploit this to scan internal network ports, interact with internal services, or bypass firewalls. The vulnerability is addressed in version 6.0.12.

Affected products

  • Themeum Kirki <= 6.0.11

Timeline

  • 2026-06-23: other: Reported by researcher Ananda Dhakal
  • 2026-06-26: disclosed: Early warning sent to Patchstack customers
  • 2026-06-26: advisory: Public advisory published by Patchstack and NVD
  • 2026-06-26: patched: Patch released in version 6.0.12

References