WPDeeply
Download free plugin
Plugin Security

Kirki ≤ 6.3.1 – Unauthenticated Stored XSS via Registration Metadata

Kirki 6.3.1 and earlier are vulnerable to unauthenticated stored XSS via registration metadata. Update to 6.3.2 and review exposed registration workflows.

Kirki CVE-2026-102173 unauthenticated stored XSS security advisory

Kirki versions 6.3.1 and earlier contain an unauthenticated stored cross-site scripting vulnerability in the plugin’s registration metadata handling. The issue is tracked as CVE-2026-102173 and carries a CVSS score of 7.2 (High). Kirki 6.3.2 contains the fix.

Vulnerability summary

Product Kirki – Freeform Page Builder, Website Builder & Customizer
Affected versions 6.3.1 and earlier
Fixed version 6.3.2
CVE CVE-2026-102173
Severity High, CVSS 7.2
Attack class Unauthenticated stored cross-site scripting
Privilege required None, when the vulnerable registration workflow is exposed
Disclosure date October 6, 2026

How the vulnerability works

According to Wordfence Intelligence, the vulnerable path is in ExceptionalElements::image_element(). A registration metadata value is concatenated into an HTML <img src="..."> attribute without sufficient output escaping. An attacker can therefore store crafted metadata that is later rendered as executable markup.

Exploitation is configuration-dependent. The vulnerable path requires all of the following:

  • Public user registration is enabled.
  • A published page contains a kirki-register element, exposing the required element nonce in public markup.
  • A Kirki users collection renders an image element bound to one of the affected registration metadata fields.

If these conditions are present, a visitor without an account can inject a stored script. The script executes when a user loads the affected collection page. Because stored XSS runs in the browser under the victim’s WordPress session, an administrator who visits the page could expose privileged actions or session data to the injected code.

Immediate remediation

  1. Update Kirki to 6.3.2 or newer immediately.
  2. Purge page, object, and CDN caches after the update.
  3. Review whether public registration is required. Disable it when it is not a business requirement.
  4. Inspect pages containing Kirki registration and user-collection elements for unexpected registration metadata or markup.
  5. Force password resets and invalidate sessions if there is evidence that an administrator viewed a compromised collection page.

Verification with WP-CLI

Check the installed Kirki version:

wp plugin get kirki --field=version

Version 6.3.1 or earlier is vulnerable. Update and confirm the installed release:

wp plugin update kirki
wp plugin get kirki --field=version

Check whether public registration is enabled:

wp option get users_can_register

A value of 1 means public registration is enabled. If registration is not required, disable it:

wp option update users_can_register 0

Temporary mitigation when an update cannot be applied

This is a temporary risk-reduction measure, not a replacement for the vendor patch. Disable public registration and remove or unpublish pages that expose the Kirki registration element until version 6.3.2 can be deployed. If registration must remain available, restrict access to the affected registration and users-collection pages at the application firewall or reverse proxy until the plugin is updated.

Security headers such as a restrictive Content Security Policy can limit some XSS impact, but they do not correct the unsafe data flow and should not be treated as the primary fix.

Post-update checks

  • Confirm Kirki reports version 6.3.2 or later.
  • Open affected registration and collection pages in a clean browser session and confirm normal rendering.
  • Review recently created users and their profile metadata for unexpected values.
  • Check access and security logs around the affected pages for unusual registration bursts or administrator visits immediately following suspicious registrations.
  • Rotate administrator sessions if compromise cannot be ruled out.

Sources

WPDeeply did not discover this vulnerability. This advisory summarizes the public Wordfence Intelligence disclosure and the vendor’s published remediation.

WPdeeply

WPDeeply is the site's editorial account for WordPress security advisories, plugin risk research, and remediation guides. Articles under this byline are checked against vendor changelogs, CVE records, vulnerability database entries, and the WPDeeply editorial policy before publication.