Junglewise Threat Intelligence

CVE-2026-57725: Themeum Kirki Stored XSS

CVE-2026-57725 · Severity: high · CVSS 7.1 · Published 2026-07-13

Technologies: Themeum Kirki. Vendors: Themeum.

Executive brief

Kirki is a popular framework used by WordPress developers to create rich customization options for themes. A security flaw in this tool allows attackers to inject malicious scripts into a website, which could lead to unauthorized actions, data theft, or site defacement when a victim views the affected page. This vulnerability can be used in automated attacks to target many websites simultaneously.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Themeum Kirki plugin for WordPress (versions up to and including 6.0.11) due to improper neutralization of input during web page generation. The flaw allows an unauthenticated attacker to inject malicious HTML or JavaScript payloads into the application. While the injection may be unauthenticated, successful exploitation requires a privileged user to interact with the affected page (User Interaction). This can result in session hijacking, unauthorized administrative actions, or redirection to malicious sites. The issue is resolved in version 6.0.12.

Affected products

  • Themeum Kirki <= 6.0.11

Timeline

  • 2026-05-19: other: Vulnerability reported by VanTastic
  • 2026-07-06: advisory: Patchstack published advisory
  • 2026-07-13: disclosed: CVE published to NVD
  • 2026-07-13: patched: Version 6.0.12 released to address the issue

References