Kirki vulnerability

The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments.

Published 6 Sep 2026Updated 6 Sep 20261 sources
CVSS 0.0

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.