CVE-2026-84219
Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments.
| Vendor | unknown |
| Product | kirki |
| Published | Sep 6, 2026 |
| Last Updated | Sep 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown kirki
Be the first to know when new high vulnerabilities affecting unknown kirki are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Kirki
6.2.1 < 6.3.0
References
Credits
Jakub Herman WPScan