Sceawere

Vulnerability Detail

CVE-2026-16974UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Kirki Customizer Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
4h ago
Vendor
themeum
Product
Kirki – Freeform Page Builder, Website Builder & Customizer
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta Shortcode in all versions up to, and including, 6.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-08-11T05:17:12.560Z",
  "pubdate": "2026-08-11T05:17:12.560Z",
  "executiveSummary": "The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability via the post_meta Shortcode mechanism.\nThe flaw impacts all plugin versions up to, and including, 6.2.0, presenting a significant security risk to deployments utilizing the software.\nThe vulnerability arises due to insufficient input sanitization and output escaping implemented within the shortcode parsing logic.\nAuthenticated attackers possessing Contributor-level access and above can exploit this weakness by injecting arbitrary web scripts and malicious payloads into pages.\nWhen an unsuspecting user accesses the injected page, the malicious script executes within the context of their browser session.\nThis can lead to severe security implications, including session hijacking, unauthorized administrative actions, and further compromise of the affected WordPress site.",
  "technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS), stemming directly from inadequate input sanitization and missing output escaping of user-supplied data handled by the post_meta Shortcode.\nThe vulnerable component resides within the shortcode processing functionality of the Kirki – Freeform Page Builder, Website Builder & Customizer plugin, affecting all versions up to, and including, 6.2.0.\nExploitation of this vulnerability requires authentication, specifically targeting users with Contributor-level access privileges or higher within the WordPress environment.\nThe attack vector involves the manipulation of post metadata processed by the shortcode.\nStep-by-step, the exploitation flow occurs as follows: First, an authenticated attacker with contributor privileges crafts a malicious payload containing arbitrary JavaScript or HTML tags.\nSecond, the attacker inserts this payload into a post or page utilizing the vulnerable post_meta Shortcode.\nThird, the application fails to properly sanitize the input upon ingestion and subsequently fails to apply context-aware output escaping when rendering the data.\nFourth, the malicious payload is persistently stored within the database.\nFinally, when a victimized user—such as an administrator or regular site visitor—loads the affected page, the server renders the unescaped script, causing the browser to execute the payload within the victim's session.\nThe post-exploitation impact includes the potential execution of arbitrary actions on behalf of the victim, theft of sensitive session cookies, redirection to malicious external sites, or administrative account takeover if an administrator views the crafted payload."
}
CVE-2026-16974: Kirki Customizer Stored XSS (MEDIUM Severity, CVSS: 6.4) - Sceawere