Sceawere
Vulnerability Detail
CVE-2026-102291UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Kirki Arbitrary Shortcode Execution
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 2h ago
- Vendor
- themeum
- Product
- Kirki – Freeform Page Builder, Website Builder & Customizer
- Attack Type
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.3.1 This is due to the plugin substituting a user's `display_name` into the composed page markup unfiltered and then running the whole result through `do_shortcode()` in `TheFrontend::replace_content()`. Because `display_name` is writable by any user on their own account through the core profile form, this makes it possible for authenticated attackers with Subscriber-level access and above to execute arbitrary shortcodes. Where the page is a users collection — an ordinary team or member-directory page — the shortcode runs in the request of every visitor, including unauthenticated ones. Requires a published page with a Kirki element whose dynamic content is bound to the `display_name` user field.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-10T08:17:03.490Z",
"pubdate": "2026-10-10T08:17:03.490Z",
"executiveSummary": "The Kirki plugin for WordPress, in versions up to and including 6.3.1, contains a critical vulnerability allowing for arbitrary shortcode execution. This security flaw stems from the insecure handling of user-supplied profile data within page content rendering.\nThe vulnerability is classified as an improper neutralization of input during web page generation. An attacker with minimal privileges (Subscriber level) can inject malicious shortcode payloads into their 'display_name' field, which the plugin subsequently processes through the 'do_shortcode()' function.\nSuccessful exploitation allows an attacker to execute arbitrary shortcodes on any page where a Kirki element dynamically displays user data. Depending on the shortcodes available in the environment, this can lead to privilege escalation, unauthorized data access, or sensitive information disclosure.\nThe risk is significantly amplified if the injected shortcode executes on publicly accessible pages, such as member directories or team pages, where the payload is triggered by every site visitor, including unauthenticated users. This requires a published page utilizing specific Kirki dynamic content bindings to manifest.",
"technicalDetails": "The root cause of this vulnerability lies within the 'TheFrontend::replace_content()' method of the Kirki plugin. The plugin retrieves the 'display_name' attribute of a user, which is a field controllable by any authenticated user via the WordPress core profile management interface. This value is then directly injected into the composed page markup without proper sanitization or escaping.\nSubsequent to this injection, the plugin passes the processed markup string, now containing the unsanitized 'display_name' value, directly into the WordPress 'do_shortcode()' function. Because WordPress shortcodes are evaluated at the time of rendering, an attacker can input a shortcode payload (e.g., [malicious_shortcode]) into their profile name field, which will be executed by the server when the Kirki-driven component is rendered.\nThe attack flow proceeds as follows: 1) An authenticated user with at least Subscriber privileges navigates to their profile and updates the 'display_name' field to include a shortcode string. 2) The attacker identifies or creates a published page that utilizes a Kirki component bound to display the 'display_name' dynamic field. 3) Upon loading the page, 'TheFrontend::replace_content()' retrieves the malicious 'display_name', embeds it into the HTML structure, and passes the entire payload to 'do_shortcode()'. 4) The server parses and executes the injected shortcode within the context of the current request.\nThe impact of this execution depends entirely on the shortcodes registered within the target WordPress environment. An attacker could potentially utilize existing shortcodes to bypass security controls, extract database information, or perform unauthorized actions. If the component is located on a public-facing page, the exploit is not limited to the attacker's session; every visitor to the page triggers the execution, creating a persistent and potentially widespread attack vector. This necessitates that the site administrator maintain strict control over user profile attributes and audit shortcode availability to prevent such exploitation paths from being utilized against the application infrastructure."
}