<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:kirki:freeform_page_builder_website_builder_customizer:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3akirkifreeform_page_builder_website_builder_customizer/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 06:34:52 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3akirkifreeform_page_builder_website_builder_customizer/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Kirki WordPress Plugin via Registration Metadata</title><link>https://feed.craftedsignal.io/briefs/2026-10-kirki-xss/</link><pubDate>Wed, 07 Oct 2026 06:34:52 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-kirki-xss/</guid><description>The Kirki plugin for WordPress is vulnerable to Stored XSS due to insufficient input validation in registration metadata, allowing unauthenticated attackers to inject malicious scripts.</description><content:encoded><![CDATA[<p>The Kirki plugin for WordPress, specifically versions up to and including 6.3.1, contains a security vulnerability identified as CVE-2026-102173. The flaw resides in the <code>ExceptionalElements::image_element()</code> method, which improperly escapes user-meta values before concatenating them into HTML <code>&lt;img&gt;</code> tag attributes. An unauthenticated attacker can exploit this by submitting malicious payloads through registration metadata fields. When a page containing a <code>kirki-register</code> element renders the affected metadata, the injected script executes in the context of the user's browser. Successful exploitation requires the target WordPress site to have public user registration enabled and to feature a page with the <code>kirki-register</code> element, which is necessary to capture the required nonces for the injection.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS). If successfully exploited, this can lead to session hijacking, unauthorized actions performed on behalf of authenticated users, or the redirection of visitors to malicious sites. The scope of impact is limited to WordPress installations utilizing the Kirki plugin where public registration is active and the specific page component is present.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the Kirki plugin to the latest patched version available.</li>
<li>Disable public user registration on WordPress sites if it is not a business requirement.</li>
<li>Monitor web server access logs for anomalous registration activity or suspicious characters in form submissions targeting user-meta fields.</li>
<li>Implement Content Security Policy (CSP) headers to mitigate the impact of potential XSS attacks by restricting the execution of inline scripts and unauthorized external sources.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>