Cross Site Scripting Vulnerability in Kirki Plugin by WordPress
CVE-2026-66629
7.1HIGH
What is CVE-2026-66629?
A Cross Site Scripting (XSS) vulnerability has been identified in the Kirki plugin for WordPress, specifically affecting versions up to 6.2.3. This vulnerability allows unauthenticated attackers to inject malicious scripts into the affected websites, potentially leading to unauthorized access or manipulation of site content. Site admins are encouraged to update to the latest version of the plugin to mitigate this security risk.
Affected Version(s)
Kirki <= 6.2.3