CVE-2026-74992
Received Received - Intake

Kirki Plugin Arbitrary File Upload and Stored XSS Vulnerability

Vulnerability report for CVE-2026-74992, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: WPScan

Description

The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all unwanted files after extracting them, allowing such users to upload arbitrary files to a web accessible directory, leading to Stored XSS as well as RCE on some server configurations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
aristath kirki to 6.2.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Kirki WordPress plugin before version 6.2.3 has a flaw where it does not properly validate files in uploaded archives. Users with the Editor role can exploit this to upload arbitrary files to a web-accessible directory. This leads to Stored Cross-Site Scripting (XSS) and potentially Remote Code Execution (RCE) on some servers because the plugin fails to remove unwanted files after extraction.

Detection Guidance

Check the installed version of the Kirki plugin in WordPress. If it is below 6.2.3, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files in the /wp-content/plugins/ directory.

Impact Analysis

If you use the vulnerable Kirki plugin, attackers with Editor access could upload malicious files to your server. This could allow them to execute arbitrary code on your server (RCE) or inject malicious scripts into your website (Stored XSS), compromising user data and site integrity.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR (data protection) and HIPAA (health data security) by exposing sensitive user information. Compliance may be compromised if attackers exfiltrate or manipulate data due to the RCE or XSS risks.

Mitigation Strategies

Update the Kirki plugin to version 6.2.3 or later immediately. Remove any unauthorized files in web-accessible directories and review user roles to ensure only trusted users have Editor access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-74992. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart