Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of input during web page generation in the Kirki plugin, which permits an attacker to store arbitrary JavaScript scripts. These scripts will be rendered whenever the plugin displays data, resulting in stored XSS.

Affected Systems

The issue affects the Themeum Kirki plugin versions up through 6.0.11. Any WordPress site that has this plugin installed and allows the plugin’s settings or custom fields to accept user input is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact. The EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation appears possible if an attacker can insert input via the plugin’s configuration interface; no information on authentication level is disclosed. The stored payload will execute for all visitors who load the affected pages.

Generated by OpenCVE AI on August 1, 2026 at 10:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Kirki plugin to a version newer than 6.0.11 to eliminate the stored XSS flaw.
  • Restrict access to the Kirki settings and custom fields to administrators, preventing non‑trusted users from entering data that can be stored.
  • Ensure that any data rendered by the plugin is properly escaped; use WordPress sanitization functions such as esc_html or wp_kses.

Generated by OpenCVE AI on August 1, 2026 at 10:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Themeum
Themeum kirki
Wordpress
Wordpress wordpress
Vendors & Products Themeum
Themeum kirki
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11.
Title WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Themeum Kirki
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:38:41.795Z

Reserved: 2026-06-25T08:04:13.263Z

Link: CVE-2026-57725

cve-icon Vulnrichment

Updated: 2026-07-13T13:54:37.897Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')