{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/kirki--freeform-page-builder-website-builder--customizer--6.3.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kirki:freeform_page_builder_website_builder_customizer:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-102173"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Kirki – Freeform Page Builder, Website Builder \u0026 Customizer (\u003c= 6.3.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Kirki"],"content_html":"\u003cp\u003eThe Kirki plugin for WordPress, specifically versions up to and including 6.3.1, contains a security vulnerability identified as CVE-2026-102173. The flaw resides in the \u003ccode\u003eExceptionalElements::image_element()\u003c/code\u003e method, which improperly escapes user-meta values before concatenating them into HTML \u003ccode\u003e\u0026lt;img\u0026gt;\u003c/code\u003e tag attributes. An unauthenticated attacker can exploit this by submitting malicious payloads through registration metadata fields. When a page containing a \u003ccode\u003ekirki-register\u003c/code\u003e element renders the affected metadata, the injected script executes in the context of the user's browser. Successful exploitation requires the target WordPress site to have public user registration enabled and to feature a page with the \u003ccode\u003ekirki-register\u003c/code\u003e element, which is necessary to capture the required nonces for the injection.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS). If successfully exploited, this can lead to session hijacking, unauthorized actions performed on behalf of authenticated users, or the redirection of visitors to malicious sites. The scope of impact is limited to WordPress installations utilizing the Kirki plugin where public registration is active and the specific page component is present.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Kirki plugin to the latest patched version available.\u003c/li\u003e\n\u003cli\u003eDisable public user registration on WordPress sites if it is not a business requirement.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous registration activity or suspicious characters in form submissions targeting user-meta fields.\u003c/li\u003e\n\u003cli\u003eImplement Content Security Policy (CSP) headers to mitigate the impact of potential XSS attacks by restricting the execution of inline scripts and unauthorized external sources.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-07T06:34:52Z","date_published":"2026-10-07T06:34:52Z","id":"https://feed.craftedsignal.io/briefs/2026-10-kirki-xss/","summary":"The Kirki plugin for WordPress is vulnerable to Stored XSS due to insufficient input validation in registration metadata, allowing unauthenticated attackers to inject malicious scripts.","title":"Stored XSS in Kirki WordPress Plugin via Registration Metadata","url":"https://feed.craftedsignal.io/briefs/2026-10-kirki-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Kirki – Freeform Page Builder, Website Builder \u0026 Customizer (\u003c= 6.3.1)","version":"https://jsonfeed.org/version/1.1"}