<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Kirki - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/kirki/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 11 Sep 2026 11:12:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/kirki/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in Kirki WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-17037/</link><pubDate>Fri, 11 Sep 2026 11:12:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-17037/</guid><description>The Kirki plugin for WordPress version 6.2.0 and below is susceptible to unauthenticated Stored Cross-Site Scripting (XSS) via the 'comment' parameter, potentially leading to unauthorized script execution in administrative or user sessions.</description><content:encoded><![CDATA[<p>The Kirki - Freeform Page Builder, Website Builder &amp; Customizer plugin for WordPress is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability. Identified as CVE-2026-17037, this flaw exists due to insufficient input sanitization and output escaping within the 'comment' parameter. The vulnerability allows unauthenticated remote attackers to inject malicious web scripts into the site's database. When a site administrator or other users navigate to the affected page, the injected JavaScript executes within their browser session. This could be leveraged to perform actions on behalf of the user, steal session cookies, or redirect users to malicious domains. The vulnerability affects all plugin versions up to and including 6.2.0. Organizations using this plugin should prioritize updating to a version that implements proper input validation and output encoding to mitigate the risk of script injection.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users' sessions. This can lead to account takeovers, unauthorized administrative actions, or the delivery of secondary payloads to visitors. As a common page-building component, the vulnerability affects a wide range of WordPress-based web properties, increasing the risk of widespread site compromise and secondary victim targeting.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate update of the Kirki plugin to the latest available version that patches the input sanitization flaw identified in CVE-2026-17037. If an immediate update is not feasible, implement a Web Application Firewall (WAF) rule to inspect and block POST requests containing suspicious script tags or JavaScript event handlers in the 'comment' parameter.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>xss</category><category>vulnerability</category></item></channel></rss>