Arbitrary Shortcode Execution in Kirki Website Builder by WordPress
CVE-2026-102291

5.4MEDIUM

What is CVE-2026-102291?

The Kirki plugin for WordPress is susceptible to a vulnerability that allows authenticated users, including those with limited Subscriber-level access, to execute arbitrary shortcodes. This occurs when a user's display name is inserted into the page content without proper filtering, subsequently processed by the do_shortcode() function. The vulnerability is particularly concerning for publicly accessible pages that utilize Kirki elements linked to the display_name user field, as it can lead to unwanted code execution that impacts all visitors, including unauthenticated users.

Affected Version(s)

Kirki – Freeform Page Builder, Website Builder & Customizer 0 <= 6.3.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dzaku
.