Arbitrary Shortcode Execution in Kirki Website Builder by WordPress
CVE-2026-102291
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-102291?
The Kirki plugin for WordPress is susceptible to a vulnerability that allows authenticated users, including those with limited Subscriber-level access, to execute arbitrary shortcodes. This occurs when a user's display name is inserted into the page content without proper filtering, subsequently processed by the do_shortcode() function. The vulnerability is particularly concerning for publicly accessible pages that utilize Kirki elements linked to the display_name user field, as it can lead to unwanted code execution that impacts all visitors, including unauthenticated users.
Affected Version(s)
Kirki β Freeform Page Builder, Website Builder & Customizer 0 <= 6.3.1