{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-102291", "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599", "state": "PUBLISHED", "assignerShortName": "Wordfence", "dateReserved": "2026-09-28T20:34:15.636Z", "datePublished": "2026-10-10T07:41:47.748Z", "dateUpdated": "2026-10-10T07:41:47.748Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599", "shortName": "Wordfence", "dateUpdated": "2026-10-10T07:41:47.748Z" }, "affected": [ { "vendor": "themeum", "product": "Kirki – Freeform Page Builder, Website Builder & Customizer", "versions": [ { "version": "0", "status": "affected", "lessThanOrEqual": "6.3.1", "versionType": "semver" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.3.1 This is due to the plugin substituting a user's `display_name` into the composed page markup unfiltered and then running the whole result through `do_shortcode()` in `TheFrontend::replace_content()`. Because `display_name` is writable by any user on their own account through the core profile form, this makes it possible for authenticated attackers with Subscriber-level access and above to execute arbitrary shortcodes. Where the page is a users collection — an ordinary team or member-directory page — the shortcode runs in the request of every visitor, including unauthenticated ones. Requires a published page with a Kirki element whose dynamic content is bound to the `display_name` user field." } ], "title": "Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'display_name'", "references": [ { "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bed93040-a843-417e-89b4-5ab3cba788aa?source=cve" }, { "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.3.1/includes/Frontend/TheFrontend.php#L144" }, { "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.3.1/includes/Frontend/Preview/Utils.php#L408" }, { "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.3.1/includes/Frontend/Preview/Utils.php#L308" }, { "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.3.1/includes/Frontend/Preview/Utils.php#L334" }, { "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.3.1/includes/HelperFunctions.php#L1117" }, { "url": "https://plugins.trac.wordpress.org/browser/kirki/tags/6.3.1/includes/Manager/PluginShortcode.php#L40" }, { "url": "https://plugins.trac.wordpress.org/changeset?reponame=&new=3718900%40kirki%2Ftags%2F6.3.2&old=3697265%40kirki%2Ftags%2F6.3.1" } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')", "cweId": "CWE-74", "type": "CWE" } ] } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", "baseScore": 5.4, "baseSeverity": "MEDIUM" } } ], "credits": [ { "lang": "en", "type": "finder", "value": "dzaku" } ], "timeline": [ { "time": "2026-09-28T20:50:31.000Z", "lang": "en", "value": "Vendor Notified" }, { "time": "2026-10-09T18:47:02.000Z", "lang": "en", "value": "Disclosed" } ] } } }