PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-102291 themeum CVE debrief

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authenticated arbitrary shortcode execution. An attacker with Subscriber-level access can exploit this by modifying their display name to include malicious shortcodes, which are then executed when a page with a Kirki element bound to the display name field is viewed.

Vendor
themeum
Product
Kirki – Freeform Page Builder, Website Builder & Customizer
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for WordPress installations with the Kirki plugin should assess exposure and prioritize verification of the display name input field. They should also review compensating controls for exposed systems while remediation is scheduled and verified, and monitor for suspicious shortcode activity. Additionally, defenders should track exceptions, retest remediated assets, and close the item only after evidence is documented.

Why it matters

Authenticated arbitrary shortcode execution in Kirki plugin allows attackers to inject malicious content and potentially elevate privileges.

  • Execution of arbitrary shortcodes by authenticated attackers
  • Potential for malicious content injection
  • Elevation of privileges through shortcode execution
  • Compromise of affected WordPress installations

Technical summary

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authenticated arbitrary shortcode execution due to unfiltered user input in the display name field. This allows attackers with Subscriber-level access to execute arbitrary shortcodes, potentially leading to malicious content injection and elevation of privileges. The vulnerability exists in all versions up to, and including, 6.3.1 of the plugin. The exploitation of this vulnerability requires a published page with a Kirki element whose dynamic content is bound to the display_name user field.

Defensive priority

Defenders should prioritize verifying the display name input field for shortcode execution and restrict access to the Kirki plugin's settings.

Recommended defensive actions

  • Verify the display name input field for shortcode execution
  • Restrict access to the Kirki plugin's settings
  • Monitor for suspicious shortcode activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including the affected plugin version and exploitation requirements. The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authenticated arbitrary shortcode execution due to unfiltered user input in the display name field. Defenders should verify the display name input field for shortcode execution and restrict access to the Kirki plugin's settings. Evidence limits are based on CVE and source-item details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-102291 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-102291

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-102291 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-102291

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Authenticated (Subscriber

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/102xxx/CVE-2026-102291.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/kirki/tags/6.3.1/includes/Frontend/TheFrontend.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/kirki/tags/6.3.1/includes/Frontend/Preview/Utils.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/kirki/tags/6.3.1/includes/HelperFunctions.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/kirki/tags/6.3.1/includes/Manager/PluginShortcode.php

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.