Impact
An unauthenticated Cross Site Scripting flaw exists in the WordPress Kirki plugin versions 6.2.3 and earlier. The vulnerability allows a malicious actor to inject arbitrary JavaScript into the plugin’s output. This can lead to session hijacking, credential theft, defacement, or execution of additional client‑side attacks against site visitors. The weakness is an input validation flaw, identified as CWE‑79.
Affected Systems
The affected system is the WordPress Kirki plugin developed by Themeum, specifically versions 6.2.3 and earlier. Users running these versions on any WordPress installation are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. EPSS data is unavailable, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is unauthenticated: an attacker can deliver malicious payloads through any input field or URL that the plugin processes without adequate sanitization. Successful exploitation would occur when a victim's browser executes the injected script.
OpenCVE Enrichment