Impact
Without authentication, an attacker can submit the "comment" parameter to the Kirki plugin and have arbitrary JavaScript stored in the database. When a user later views a page containing the stored comment, the browser will execute the injected script, leading to client‑side code execution on that user’s machine.
Affected Systems
WordPress sites that run the Kirki – Freeform Page Builder, Website Builder & Customizer plugin from Themeum, any version up to and including 6.2.0.
Risk and Exploitability
The vulnerability has a CVSS score of 7.2, categorizing it as High risk. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog. Because the exploitation does not require authentication and operates through a public input field, an attacker can easily deploy the payload and the stored script will run for any subsequent visitor to the affected page.
OpenCVE Enrichment