Sceawere

Vulnerability Detail

CVE-2026-102173UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in Kirki Plugin

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
4h ago
Vendor
themeum
Product
Kirki – Freeform Page Builder, Website Builder & Customizer
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via registration metadata in all versions up to, and including, 6.3.1 This is due to insufficient escaping in `ExceptionalElements::image_element()`, which concatenates a user-meta value straight into an `<img src="…">` attribute. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute whenever a user accesses a page rendering a Kirki users collection whose image element is bound to one of the nine registration meta fields. Requires public user registration to be enabled and a published page carrying a `kirki-register` element, which prints the required element nonce into the public markup.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-07T06:16:33.217Z",
  "pubdate": "2026-10-07T06:16:33.217Z",
  "executiveSummary": "The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability affecting versions up to and including 6.3.1.\nThe vulnerability originates from improper neutralization of input within registration metadata, specifically via the ExceptionalElements::image_element() function.\nAn unauthenticated attacker can exploit this flaw to inject malicious JavaScript into user-meta fields, which executes when an administrator or user views a page rendering the affected Kirki users collection.\nSuccessful exploitation requires that public user registration is enabled on the target WordPress instance and that a page containing the 'kirki-register' element is published, which exposes the necessary nonce.\nThe impact includes potential account takeover, session hijacking, or unauthorized administrative actions performed in the context of the victim's browser session. The risk level is significant due to the ability for unauthenticated actors to execute arbitrary code within the victim's browser environment.",
  "technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS), stemming from the unsafe handling of user-controlled input in the ExceptionalElements::image_element() function. In affected versions (up to 6.3.1), the plugin retrieves user-meta values and directly concatenates them into the 'src' attribute of an HTML <img> tag without adequate output escaping or sanitization.\nThe attack vector leverages the WordPress user registration process. If public registration is enabled, an unauthenticated attacker can supply malicious payloads within the registration meta fields. The plugin's architecture processes these fields when rendering the 'kirki-register' element on a public-facing page.\nTo trigger the execution, an attacker must first identify a published page containing the 'kirki-register' element. This element serves as the trigger mechanism because it facilitates the printing of a required element nonce into the DOM. Once the attacker performs registration with the injected malicious payload in one of the nine susceptible registration meta fields, the payload is stored persistently in the database.\nWhen a victim, such as an administrator or another user, navigates to a page where the Kirki users collection is rendered, the vulnerable function retrieves the tainted meta data. Because the data is inserted directly into the image source attribute, an attacker can break out of the intended attribute context—for example, by utilizing 'onerror' event handlers or JavaScript URI schemes—to execute arbitrary JavaScript.\nThe execution occurs within the security context of the victim's session. This allows an attacker to perform actions such as stealing session cookies, capturing sensitive information, or forcing the victim to perform unauthorized administrative operations. Because the vulnerability relies on stored data, the payload will execute every time the affected element is rendered, leading to persistent risk until the underlying meta data is cleansed or the plugin is updated to implement proper escaping functions such as esc_url() or esc_attr() within the ExceptionalElements::image_element() method."
}
CVE-2026-102173: Stored XSS in Kirki Plugin (HIGH Severity, CVSS: 7.2) | Sceawere