
🚨*CVE* CVE-2026-16974 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta Shortcode in all v… https://www.cve.org/CVERecord?id=CVE-2026-16974 ----- Traducción: CVE-2026-16974 El … http://infoflow.cloud`
Post summary
The post alerts that the Kirki WordPress plugin is vulnerable to stored XSS through the post_meta shortcode, linking to the CVE record but providing no PoC, exploit code, or patch details.

