Junglewise Threat Intelligence

CVE-2026-57726: Themeum Kirki blind SQL injection

CVE-2026-57726 · Severity: critical · CVSS 9.3 · Published 2026-07-13

Technologies: Themeum Kirki. Vendors: Themeum.

Executive brief

Themeum Kirki is a popular WordPress framework used by developers to create customization options for themes. A critical security flaw allows unauthenticated attackers to perform 'blind' SQL injection attacks, which means they can trick the website's database into revealing sensitive information. This could lead to the theft of customer data or administrative credentials, potentially compromising the entire website.

Technical details

A Blind SQL Injection vulnerability exists in the Themeum Kirki plugin for WordPress (versions up to and including 6.0.12). The flaw stems from improper neutralization of user-supplied input used within SQL commands. An unauthenticated remote attacker can exploit this by sending specially crafted web requests to trigger boolean-based or time-based inference attacks against the database. Successful exploitation allows the attacker to extract sensitive information from the WordPress database. The issue is resolved in version 6.0.13.

Affected products

  • Themeum Kirki <= 6.0.12

Timeline

  • 2026-05-20: disclosed: Reported by researcher daroo
  • 2026-07-06: advisory: Patchstack published advisory
  • 2026-07-13: patched: Version 6.0.13 released to address the vulnerability

References

Related threats