Junglewise Threat Intelligence

CVE-2026-57680: Themeum Kirki IDOR in WordPress plugin

CVE-2026-57680 · Severity: medium · CVSS 6.5 · Published 2026-07-02

Technologies: Themeum Kirki. Vendors: Themeum.

Executive brief

Kirki is a popular framework used by WordPress developers to create customization options for themes. A security flaw in versions 6.0.11 and earlier allows unauthorized individuals to bypass security checks and potentially modify site settings or interact with the database without logging in. This could lead to unauthorized changes to a website's appearance or functionality, impacting the site's integrity and operational stability.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the Kirki Customizer Framework plugin for WordPress (versions up to 6.0.11). The flaw is categorized under CWE-639, where the application does not sufficiently verify the authorization of a user providing a direct reference to an internal object. An unauthenticated remote attacker can exploit this by sending crafted requests to interact with or modify objects they should not have access to. This can result in unauthorized data modification or service disruption. The issue is resolved in version 6.0.12.

Affected products

  • Themeum Kirki Customizer Framework <= 6.0.11

Timeline

  • 2026-05-19: disclosed: Reported by VanTastic
  • 2026-06-30: advisory: Patchstack published advisory
  • 2026-07-02: patched: NVD publication and confirmation of version 6.0.12 as the fix

References