Impact
The Kirki plugin performs an unfiltered substitution of a user's display_name into page markup and then passes the entire result to WordPress's do_shortcode() function. Because the display_name field can be edited by any user on their own profile, authenticated users with the Subscriber role or higher can insert any shortcode they choose. If a page contains a Kirki element bound to display_name, the attacker’s shortcode runs in the context of the page request, potentially allowing code execution or other malicious actions on the site. The CVSS score of 5.4 indicates a moderate severity for this authenticated flaw.
Affected Systems
The vulnerability affects the themeum Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress in all releases up to and including version 6.3.1. The issue is present only on sites that have published pages containing a Kirki element bound to the user display_name field.
Risk and Exploitability
The CVSS score of 5.4 reflects a moderate risk, and the lack of EPSS data means the likelihood of exploitation is currently unknown. The vulnerability is not listed in the CISA KEV catalog. An attacker needs Subscriber-level or higher authenticated access to inject the malicious shortcode. Once injected, the shortcode will be executed for every visitor to the page, including unauthenticated users, which elevates the potential impact to widespread compromise if the attacker chooses a shortcode that performs server-side actions or leaks sensitive data.
OpenCVE Enrichment