The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 06 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Sun, 06 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments. | |
| Title | Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-06T06:00:04.619Z
Reserved: 2026-09-01T11:50:19.947Z
Link: CVE-2026-84219
No data.
Status : Received
Published: 2026-09-06T07:16:43.427
Modified: 2026-09-06T07:16:43.427
Link: CVE-2026-84219
No data.
OpenCVE Enrichment
Updated: 2026-09-06T07:30:03Z
Weaknesses