The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Kirki WordPress plugin before version 6.0.12 contains a critical Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to exploit inadequate URL validation. When the plugin processes user-supplied URLs without proper sanitization, an attacker can craft malicious requests that force the vulnerable WordPress server to make HTTP calls to arbitrary internal or external hosts. This vulnerability affects any WordPress installation using the affected Kirki plugin versions, potentially exposing internal services, metadata endpoints, cloud credentials, and sensitive data accessible only from the server's network context. With a CVSS score of 9.1, this represents a critical risk that can lead to information disclosure, lateral movement, and further compromise of the hosting infrastructure.
While this specific CVE currently has no mapped MITRE ATT&CK techniques, Casky's Claude-powered analysis would identify the underlying attack patterns associated with SSRF exploitation, including reconnaissance of internal services (T1592 - Gather Victim Network Information), exploitation of trust relationships (T1199 - Trusted Relationship), and potential access to cloud metadata services (T1526 - Cloud Service Discovery). Security practitioners monitoring their environments through Casky would observe suspicious outbound HTTP requests from their WordPress server to unexpected internal IP ranges or cloud metadata endpoints, unusual request patterns from the web server process, and potential access logs showing requests to localhost services or RFC 1918 addresses. Detection would focus on analyzing HTTP request logs for unvalidated URL parameters being processed server-side and monitoring for anomalous external connectivity initiated by the WordPress application.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-13147. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation