Impact
The vulnerability in the Kirki plugin allows an unauthenticated attacker to store malicious JavaScript code in the user registration metadata. When a page renders a Kirki image element that references one of the nine registration meta fields, the unsanitized value is concatenated directly into an img src attribute, causing the injected script to run in the browser of any visitor. This leads to a classic stored XSS impact: arbitrary code execution in the context of the site, with potential for session hijacking, credential theft, defacement, or further phishing attacks.
Affected Systems
The issue affects all WordPress installations that use the themeum Kirki – Freeform Page Builder, Website Builder & Customizer plugin version 6.3.1 or earlier. No other products are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.2 indicates moderate‑to‑high severity, and the vulnerability is publicly exploitable because it requires only a public user registration to be enabled and a page that contains a kirki-register element to be accessible. Although EPSS data is not available, the lack of a KEV listing suggests the exploit is not yet widely observed, but the vector remains valid and straightforward for automated exploitation. The risk therefore remains significant for any site that has turned on public registration and publishes pages with Kirki elements.
OpenCVE Enrichment