Stored Cross-Site Scripting in Kirki Page Builder by WordPress
CVE-2026-17037
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 September 2026
What is CVE-2026-17037?
The Kirki β Freeform Page Builder, Website Builder & Customizer plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability in its 'comment' parameter. This arises from inadequate input sanitization and output escaping in all versions up to and including 6.2.0. As a result, unauthenticated adversaries can inject malicious web scripts into pages, enabling the execution of these scripts whenever a user accesses the compromised page, posing significant risks to website integrity and user safety.
Affected Version(s)
Kirki β Freeform Page Builder, Website Builder & Customizer 0 <= 6.2.0