WP Security CheckVulnerability data as of October 10, 2026

Vulnerability alerts / October 9, 2026

Vulnerability in Kirki – Freeform Page Builder, Website Builder & Customizer — CVE-2026-102291

MediumSeverity
CVSS 5.4
—Estimated exploit probability
EPSS
500,000+ sitesInstalls
6.3.2Fixed in

What to do now

Update Kirki – Freeform Page Builder, Website Builder & Customizer to 6.3.2 or later.

Affected versions

  • Everything up to and including 6.3.1

Affected: Kirki – Freeform Page Builder, Website Builder & Customizer (plugin, kirki)

Check: The plugin on wordpress.org / Our record for Kirki – Freeform Page Builder, Website Builder & Customizer

What the vulnerability is

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.3.1 This is due to the plugin substituting a user's `display_name` into the composed page markup unfiltered and then running the whole result through `do_shortcode()` in `TheFrontend::replace_content()`. Because `display_name` is writable by any user on their own account through the core profile form, this makes it possible for authenticated attackers with Subscriber-level access and above to execute arbitrary shortcodes. Where the page is a users collection — an ordinary team or member-directory page — the shortcode runs in the request of every visitor, including unauthenticated ones. Requires a published page with a Kirki element whose dynamic content is bound to the `display_name` user field.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/bed93040-a843-417e-89b4-5ab3cba788aa
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts