Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-74992— Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload

AI Predicted 8.8 Difficulty: Easy EPSS 0.29% · P22

Affected Version Matrix 1

VendorProductVersion RangeStatus
UnknownKirki< 6.2.3affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-74992

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload
Source: CVE Program / CVE List V5
Vulnerability Description
The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all unwanted files after extracting them, allowing such users to upload arbitrary files to a web accessible directory, leading to Stored XSS as well as RCE on some server configurations.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
UnknownKirki 0 ~ 6.2.3 -

II. Public POCs for CVE-2026-74992

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-74992

登录查看更多情报信息。

Vendor Advisories for CVE-2026-74992 (1)

Same Patch Batch · Unknown · 2026-08-20 · 7 CVEs total

CVE-2026-75860JSON Options <= 0.0.4 - Unauthenticated Arbitrary Options Update
CVE-2026-19699GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure
CVE-2026-19615Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC
CVE-2026-19697GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload
CVE-2026-15049Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import
CVE-2026-13405Royal Elementor Addons < 1.7.1066 - Admin+ Remote Code Execution via Widget Builder

IV. Related Vulnerabilities

V. Comments for CVE-2026-74992

No comments yet


Leave a comment