Junglewise Threat Intelligence

CVE-2026-74992: Kirki WordPress plugin arbitrary file upload to Stored XSS and RCE

CVE-2026-74992 · Severity: medium · CVSS 6.8 · Published 2026-08-20

Vendors: Kirki.

Executive brief

Kirki is a popular WordPress theme customization plugin. The plugin fails to properly validate and clean up files extracted from ZIP archives uploaded by editors, allowing them to upload malicious files—including HTML, SVG, and PHP—to a publicly accessible directory. This can lead to cross-site scripting attacks against site visitors or remote code execution on servers using Apache with mod_php.

Technical details

The Kirki plugin before version 6.2.3 contains an arbitrary file upload vulnerability in its font ZIP upload handler (kirki_post_apis endpoint with upload-font-zip action). The vulnerability arises from insufficient validation of archive contents and incomplete cleanup after extraction—the plugin only removes unwanted files at the top level of the extracted directory, not in subdirectories. An authenticated user with the Editor role can craft a malicious ZIP containing a valid stylesheet.css and font file (to bypass initial validation) plus arbitrary payload files (HTML, SVG, .htaccess, etc.) in subdirectories, which are then extracted to a web-accessible directory (/wp-content/uploads/kirki-fonts/). No administrator action is required since Kirki grants Editor-level users full plugin access at activation. An unauthenticated attacker can then fetch and execute these planted files—stored XSS via HTML/SVG, or RCE via .htaccess+PHP on Apache configurations permitting it. The fix is available in version 6.2.3.

Affected products

  • Kirki Kirki before 6.2.3

Timeline

  • 2026-08-18: disclosed
  • 2026-08-20: patched: version 6.2.3

References