Impact
The Kirki WordPress plugin version 6.2.2 and earlier fails to validate files inside archives uploaded by users with the Editor role. Because the plugin does not delete all unwanted files after extraction, those files can be placed in a web‑accessible directory, allowing an attacker to trigger stored cross‑site scripting and potentially execute arbitrary code on the server in some configurations. This flaw corresponds to the classic Cross‑Site Scripting weakness, CWE‑79.
Affected Systems
Any WordPress installation running the Kirki plugin at a version earlier than 6.2.3 is affected. The vendor is identified as Unknown:Kirki, and the flaw is present in all releases before 6.2.3, regardless of other plugins or themes.
Risk and Exploitability
With a CVSS base score of 6.8, the vulnerability represents moderate to high severity. Its EPSS score of less than 1% indicates a low probability of exploitation, but because an authenticated user with Editor privileges can upload a crafted archive, the detection and prevention burden falls on site administrators. The flaw is not listed in CISA’s KEV catalog, yet the ability to exploit it from within the site remains a tangible risk for WordPress sites that allow user‑generated content in the Kirki archive upload interface.
OpenCVE Enrichment