CVE-2026-102173 - Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Unauthenticated Stored Cross-Site Scripting via Registration Metadata
CVE ID :CVE-2026-102173
Published : Oct. 7, 2026, 5:30 a.m. | 15 minutes ago
Description :The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via registration metadata in all versions up to, and including, 6.3.1 This is due to insufficient escaping in `ExceptionalElements::image_element()`, which concatenates a user-meta value straight into an `
` attribute. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute whenever a user accesses a page rendering a Kirki users collection whose image element is bound to one of the nine registration meta fields. Requires public user registration to be enabled and a published page carrying a `kirki-register` element, which prints the required element nonce into the public markup.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 7, 2026, 5:30 a.m. | 15 minutes ago
Description :The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via registration metadata in all versions up to, and including, 6.3.1 This is due to insufficient escaping in `ExceptionalElements::image_element()`, which concatenates a user-meta value straight into an `
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...