Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102291— Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'display_name'

Quick assessment

Affected
themeum Kirki – Freeform Page Builder, Website Builder & Customizer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件 Kirki – Freeform Page Builder, Website Builder & Customizer 在所有不超过 6.3.1 的版本中存在任意短代码执行漏洞。该漏洞是由于插件将用户的 (显示名称)未经过滤地插入到生成的页面标记中,然后在 方法中将整个结果通过 函数执行所致。由于任何用户都可以通过核心的个人资料表单修改其自己的 ,因此,拥有 Subscriber(订阅者)及以上权限的已认证攻击者能够执行任意短代码。当页面是用户集合页面——例如普通的团队页面或成员目录页面时

CVSS 5.4 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102291

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'display_name'
Source: CVE Program / CVE List V5
Vulnerability Description
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.3.1 This is due to the plugin substituting a user's `display_name` into the composed page markup unfiltered and then running the whole result through `do_shortcode()` in `TheFrontend::replace_content()`. Because `display_name` is writable by any user on their own account through the core profile form, this makes it possible for authenticated attackers with Subscriber-level access and above to execute arbitrary shortcodes. Where the page is a users collection — an ordinary team or member-directory page — the shortcode runs in the request of every visitor, including unauthenticated ones. Requires a published page with a Kirki element whose dynamic content is bound to the `display_name` user field.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
themeum Kirki – Freeform Page Builder, Website Builder & Customizer 0 ~ 6.3.1 -

II. Public POCs for CVE-2026-102291

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102291

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-102291 (2)

Other References for CVE-2026-102291 (5)

IV. Related Vulnerabilities

V. Comments for CVE-2026-102291

No comments yet


Leave a comment