← WordPress Vulnerabilities
WordPress security by component

Kirki – Freeform Page Builder, Website Builder & Customizer

Kirki – Freeform Page Builder, Website Builder & Customizer (kirki-freeform-page-builder-website-builder-customizer) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 7.2.

Plugin slug: kirki-freeform-page-builder-website-builder-customizer

CVE-2026-17037: Kirki permits unauthenticated stored XSS through comments

Kirki through 6.2.0 does not sufficiently sanitize and escape the comment parameter before stored output. An unauthenticated attacker can inject script into a page, and the code executes whenever a user accesses the affected page. The authoritative export identifies the parameter but does not disclose the submission endpoint, storage function, or output context.

PublishedSep 11, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for kirki-freeform-page-builder-website-builder-customizer
Safe version
Sep 11, 2026 CVE-2026-17037
Kirki permits unauthenticated stored XSS through comments
Kirki through 6.2.0 does not sufficiently sanitize and escape the comment parameter before stored output. An unauthenticated attacker can inject script into a page, and the code executes whenever a user accesses the affected page. The authoritative export identifies the parameter but does not disclose the submission endpoint, storage function, or output context.
See mitigation notes
CVE7.2
NVDPending