Impact
The vulnerability arises from improper neutralization of input during web page generation in the Kirki plugin, which permits an attacker to store arbitrary JavaScript scripts. These scripts will be rendered whenever the plugin displays data, resulting in stored XSS.
Affected Systems
The issue affects the Themeum Kirki plugin versions up through 6.0.11. Any WordPress site that has this plugin installed and allows the plugin’s settings or custom fields to accept user input is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact. The EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation appears possible if an attacker can insert input via the plugin’s configuration interface; no information on authentication level is disclosed. The stored payload will execute for all visitors who load the affected pages.
OpenCVE Enrichment