Back

MEDIUM

Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload

Published Aug 20, 2026

Description

The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all unwanted files after extracting them, allowing such users to upload arbitrary files to a web accessible directory, leading to Stored XSS as well as RCE on some server configurations.

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Aug 20, 2026
Updated Aug 20, 2026
Reserved Aug 17, 2026
CISA Vulnrichment
Updated Aug 20, 2026
NVD
Status Deferred
Modified Aug 26, 2026
Red Hat
Severity n/a
Public date n/a