CVE-2026-84219
Received
Received - Intake
Stored XSS in Kirki WordPress Plugin
Vulnerability report for CVE-2026-84219, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-06
Last updated on: 2026-09-06
Assigner: WPScan
Description
Description
The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| aristath | kirki | to 6.3.0 (exc) |
| aristath | kirki | 6.2.1 |
| aristath | kirki | 6.2.2 |
| aristath | kirki | 6.2.3 |
| aristath | kirki | 6.2.4 |
| aristath | kirki | 6.2.5 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |