Junglewise Threat Intelligence

CVE-2026-57724: Themeum Kirki PHP object injection via untrusted deserialization

CVE-2026-57724 · Severity: critical · CVSS 9.8 · Published 2026-07-13

Technologies: Themeum Kirki. Vendors: Themeum.

Executive brief

Themeum Kirki is a popular WordPress framework used by developers to create customization options for themes. A critical security flaw allows unauthenticated attackers to inject malicious objects into the application's memory. If exploited, this could lead to full site takeover, unauthorized data access, or the execution of arbitrary code, potentially impacting any website using a theme built with this framework.

Technical details

A Deserialization of Untrusted Data vulnerability (CWE-502) exists in the Themeum Kirki plugin for WordPress up to and including version 6.0.12. The flaw allows for PHP Object Injection when the application processes specially crafted input without proper validation. An unauthenticated remote attacker can exploit this by sending a malicious payload that, if a suitable POP (Property Oriented Programming) chain is present on the server, could result in arbitrary code execution, file deletion, or sensitive data exposure. The issue is resolved in version 6.0.13.

Affected products

  • Themeum Kirki <= 6.0.12

Timeline

  • 2026-05-19: disclosed: Vulnerability reported by VanTastic
  • 2026-07-06: advisory: Patchstack published advisory and mitigation rules
  • 2026-07-13: patched: CVE published and version 6.0.13 confirmed as patched

References