WP Security CheckVulnerability data as of October 7, 2026

Vulnerability alerts / October 6, 2026

Vulnerability in Kirki – Freeform Page Builder, Website Builder & Customizer — CVE-2026-102173

HighSeverity
CVSS 7.2
—Estimated exploit probability
EPSS
500,000+ sitesInstalls
6.3.2Fixed in

What to do now

Update Kirki – Freeform Page Builder, Website Builder & Customizer to 6.3.2 or later.

Affected versions

  • Everything up to and including 6.3.1

Affected: Kirki – Freeform Page Builder, Website Builder & Customizer (plugin, kirki)

Check: The plugin on wordpress.org / Our record for Kirki – Freeform Page Builder, Website Builder & Customizer

What the vulnerability is

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via registration metadata in all versions up to, and including, 6.3.1 This is due to insufficient escaping in `ExceptionalElements::image_element()`, which concatenates a user-meta value straight into an `<img src="…">` attribute. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute whenever a user accesses a page rendering a Kirki users collection whose image element is bound to one of the nine registration meta fields. Requires public user registration to be enabled and a published page carrying a `kirki-register` element, which prints the required element nonce into the public markup.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/368001e9-3806-41d5-902e-0facf7fb31ff
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts