
🛠 Kirki の脆弱性が修正されました(深刻度 高) 50万サイト以上が利用 / CVSS 7.2 6.3.2 に更新してください https://shindan.m-g-n.me/alerts/cve-2026-102173/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via registration metadata in all versions up to, and including, 6.3.1 This is due to insufficient escaping in `ExceptionalElements::image_element()`, which concatenates a user-meta value straight into an `<img src="…">` attribute. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute whenever a user accesses a page rendering a Kirki users collection whose image element is bound to one of the nine registration meta fields. Requires public user registration to be enabled and a published page carrying a `kirki-register` element, which prints the required element nonce into the public markup.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🛠 Kirki の脆弱性が修正されました(深刻度 高) 50万サイト以上が利用 / CVSS 7.2 6.3.2 に更新してください https://shindan.m-g-n.me/alerts/cve-2026-102173/