Stored Cross-Site Scripting Vulnerability in Kirki Page Builder Plugin for WordPress
CVE-2026-102173

7.2HIGH

What is CVE-2026-102173?

The Kirki Page Builder plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) through user registration metadata. This vulnerability arises from insufficient escaping in the image element rendering process. An attacker could exploit this flaw to insert malicious web scripts in the metadata, which may execute when a user visits a page tied to a particular Kirki user collection. For an exploit to succeed, public user registration must be enabled, and the affected page must utilize the kirki-register element, exposing the application to potential attacks.

Affected Version(s)

Kirki – Freeform Page Builder, Website Builder & Customizer 0 <= 6.3.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hippolyte Quéré (Hippie) (Hippie)
.