Impact
Kirki before version 6.3.1 fails to sanitize SVG uploads, allowing any author‑level or higher user to upload a file that contains executable JavaScript. The plugin then serves the uploaded SVG from the site’s own domain, enabling the script to run in the browser context of any visitor who opens the file. This stored XSS can compromise user sessions, deface content, or steal data, and is classified as a classic stored XSS weakness (CWE‑79).
Affected Systems
The vulnerability affects sites that use the Kirki WordPress plugin versions 6.0.0 through 6.3.0 inclusive. Users with author‑level or higher permissions are able to upload the malicious SVG; all users who view the uploaded file become victims. No specific platform versions are listed, so any WordPress installation running an affected plugin version is impacted.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity, while the EPSS score of < 1% indicates a very low likelihood of exploitation. The CVE is not listed in the CISA KEV catalog, suggesting no confirmed exploitation to date. Attackers would need either an authenticated author account or a method to obtain one (e.g., credential compromise or social engineering). Once an author uploads the malicious SVG, the risk materializes for every site visitor who opens the file, creating a pervasive but site‑wide threat.
OpenCVE Enrichment