Stored Cross-Site Scripting Vulnerability in Kirki Page Builder Plugin for WordPress
CVE-2026-102173
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 October 2026
What is CVE-2026-102173?
The Kirki Page Builder plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) through user registration metadata. This vulnerability arises from insufficient escaping in the image element rendering process. An attacker could exploit this flaw to insert malicious web scripts in the metadata, which may execute when a user visits a page tied to a particular Kirki user collection. For an exploit to succeed, public user registration must be enabled, and the affected page must utilize the kirki-register element, exposing the application to potential attacks.
Affected Version(s)
Kirki – Freeform Page Builder, Website Builder & Customizer 0 <= 6.3.1