Junglewise Threat Intelligence

CVE-2026-16974: Kirki Freeform Page Builder Stored XSS in post_meta Shortcode

CVE-2026-16974 · Severity: medium · CVSS 6.4 · Published 2026-08-11

Technologies: Firjan Kirki.

Executive brief

The Kirki plugin is a page builder and customizer tool used by WordPress administrators to design website pages. A flaw in how it handles user-supplied content allows attackers with contributor-level access or higher to inject malicious scripts into pages. When site visitors view these compromised pages, the injected scripts execute in their browsers, potentially stealing credentials, session tokens, or performing actions on their behalf.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the post_meta Shortcode handler affecting Kirki versions up to 6.2.0. The root cause is insufficient input sanitization and output escaping of user-supplied data. An authenticated attacker with Contributor-level permissions or above can inject arbitrary JavaScript into page metadata via the post_meta Shortcode parameter. The injected script persists in the database and executes in the browsers of all users who access the affected page. No user interaction beyond normal site browsing is required for exploitation; the XSS payload fires automatically when the page is viewed.

Affected products

  • Firjan Kirki up to and including 6.2.0

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: advisory

References