Stored XSS in Kirki WordPress Plugin via Registration Metadata
The Kirki plugin for WordPress is vulnerable to Stored XSS due to insufficient input validation in registration metadata, allowing unauthenticated attackers to inject malicious scripts.
CVE search metadata
CVE search record: CVE-2026-102173. Severity: high. CVSS: 7.2. KEV: no. Product: Kirki – Freeform Page Builder, Website Builder & Customizer (<= 6.3.1). Brief: Stored XSS in Kirki WordPress Plugin via Registration Metadata. Brief link: https://feed.craftedsignal.io/briefs/2026-10-kirki-xss/
The Kirki plugin for WordPress, specifically versions up to and including 6.3.1, contains a security vulnerability identified as CVE-2026-102173. The flaw resides in the ExceptionalElements::image_element() method, which improperly escapes user-meta values before concatenating them into HTML <img> tag attributes. An unauthenticated attacker can exploit this by submitting malicious payloads through registration metadata fields. When a page containing a kirki-register element renders the affected metadata, the injected script executes in the context of the user's browser. Successful exploitation requires the target WordPress site to have public user registration enabled and to feature a page with the kirki-register element, which is necessary to capture the required nonces for the injection.
Impact
The vulnerability allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS). If successfully exploited, this can lead to session hijacking, unauthorized actions performed on behalf of authenticated users, or the redirection of visitors to malicious sites. The scope of impact is limited to WordPress installations utilizing the Kirki plugin where public registration is active and the specific page component is present.
Recommendation
- Upgrade the Kirki plugin to the latest patched version available.
- Disable public user registration on WordPress sites if it is not a business requirement.
- Monitor web server access logs for anomalous registration activity or suspicious characters in form submissions targeting user-meta fields.
- Implement Content Security Policy (CSP) headers to mitigate the impact of potential XSS attacks by restricting the execution of inline scripts and unauthorized external sources.
Immediate actions
Upgrade Kirki to the latest version to patch CVE-2026-102173
Mitigations
Disable public user registration if not strictly required
CVE-2026-102173