Junglewise Threat Intelligence

CVE-2026-66629: Kirki unauthenticated cross-site scripting

CVE-2026-66629 · Severity: high · CVSS 7.1 · Published 2026-08-18

Vendors: Kirki.

Executive brief

Kirki is a popular WordPress customizer theme and plugin framework used to customize the appearance and behavior of WordPress sites. An unauthenticated attacker can inject malicious JavaScript code that executes in the browsers of site visitors, allowing them to steal user session cookies, redirect visitors, or hijack administrator accounts. No user authentication is required to exploit this vulnerability.

Technical details

This is a reflected or stored cross-site scripting (XSS) vulnerability in Kirki versions 6.2.4 and earlier. The vulnerability exists because user-controlled input is not properly sanitized or escaped before being rendered in the browser. An unauthenticated attacker can inject malicious scripts through a crafted link or form submission, which execute with the privileges of the visiting user. Successful exploitation can lead to session hijacking, credential theft, or redirection to malicious sites. The vulnerability has been patched in version 6.2.5 and later; users should update immediately.

Affected products

  • Kirki Kirki <=6.2.4

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Patched in version 6.2.5

References