WordPress security by component
Kirki – Freeform Page Builder, Website Builder & Customizer
Kirki – Freeform Page Builder, Website Builder & Customizer (kirki-freeform-page-builder-website-builder-customizer) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 7.2.
Plugin slug:
kirki-freeform-page-builder-website-builder-customizerLatest vulnerability
CVE-2026-17037: Kirki permits unauthenticated stored XSS through comments
Kirki through 6.2.0 does not sufficiently sanitize and escape the comment parameter before stored output. An unauthenticated attacker can inject script into a page, and the code executes whenever a user accesses the affected page. The authoritative export identifies the parameter but does not disclose the submission endpoint, storage function, or output context.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-17037
Kirki permits unauthenticated stored XSS through comments
Kirki through 6.2.0 does not sufficiently sanitize and escape the comment parameter before stored output. An unauthenticated attacker can inject script into a page, and the code executes whenever a user accesses the affected page. The authoritative export identifies the parameter but does not disclose the submission endpoint, storage function, or output context.
|
See mitigation notes |
CVE7.2
NVDPending
|