Product
The Kirki plugin for WordPress version 6.2.0 and below is susceptible to unauthenticated Stored Cross-Site Scripting (XSS) via the 'comment' parameter, potentially leading to unauthorized script execution in administrative or user sessions.