๐Ÿ” CVE Alert

CVE-2026-84219

HIGH 7.5

Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments.

Vendor unknown
Product kirki
Published Sep 6, 2026
Last Updated Sep 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown kirki

Be the first to know when new high vulnerabilities affecting unknown kirki are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Kirki
6.2.1 < 6.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/e95bd1e3-6f61-423f-add6-519e1ca7bf66/

Credits

Jakub Herman WPScan