Sceawere
Vulnerability Detail
CVE-2026-102173UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Kirki Plugin
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 4h ago
- Vendor
- themeum
- Product
- Kirki – Freeform Page Builder, Website Builder & Customizer
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via registration metadata in all versions up to, and including, 6.3.1 This is due to insufficient escaping in `ExceptionalElements::image_element()`, which concatenates a user-meta value straight into an `<img src="…">` attribute. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute whenever a user accesses a page rendering a Kirki users collection whose image element is bound to one of the nine registration meta fields. Requires public user registration to be enabled and a published page carrying a `kirki-register` element, which prints the required element nonce into the public markup.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-07T06:16:33.217Z",
"pubdate": "2026-10-07T06:16:33.217Z",
"executiveSummary": "The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability affecting versions up to and including 6.3.1.\nThe vulnerability originates from improper neutralization of input within registration metadata, specifically via the ExceptionalElements::image_element() function.\nAn unauthenticated attacker can exploit this flaw to inject malicious JavaScript into user-meta fields, which executes when an administrator or user views a page rendering the affected Kirki users collection.\nSuccessful exploitation requires that public user registration is enabled on the target WordPress instance and that a page containing the 'kirki-register' element is published, which exposes the necessary nonce.\nThe impact includes potential account takeover, session hijacking, or unauthorized administrative actions performed in the context of the victim's browser session. The risk level is significant due to the ability for unauthenticated actors to execute arbitrary code within the victim's browser environment.",
"technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS), stemming from the unsafe handling of user-controlled input in the ExceptionalElements::image_element() function. In affected versions (up to 6.3.1), the plugin retrieves user-meta values and directly concatenates them into the 'src' attribute of an HTML <img> tag without adequate output escaping or sanitization.\nThe attack vector leverages the WordPress user registration process. If public registration is enabled, an unauthenticated attacker can supply malicious payloads within the registration meta fields. The plugin's architecture processes these fields when rendering the 'kirki-register' element on a public-facing page.\nTo trigger the execution, an attacker must first identify a published page containing the 'kirki-register' element. This element serves as the trigger mechanism because it facilitates the printing of a required element nonce into the DOM. Once the attacker performs registration with the injected malicious payload in one of the nine susceptible registration meta fields, the payload is stored persistently in the database.\nWhen a victim, such as an administrator or another user, navigates to a page where the Kirki users collection is rendered, the vulnerable function retrieves the tainted meta data. Because the data is inserted directly into the image source attribute, an attacker can break out of the intended attribute context—for example, by utilizing 'onerror' event handlers or JavaScript URI schemes—to execute arbitrary JavaScript.\nThe execution occurs within the security context of the victim's session. This allows an attacker to perform actions such as stealing session cookies, capturing sensitive information, or forcing the victim to perform unauthorized administrative operations. Because the vulnerability relies on stored data, the payload will execute every time the affected element is rendered, leading to persistent risk until the underlying meta data is cleansed or the plugin is updated to implement proper escaping functions such as esc_url() or esc_attr() within the ExceptionalElements::image_element() method."
}