PatchSiren cyber security CVE debrief
CVE-2026-102291 themeum CVE debrief
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authenticated arbitrary shortcode execution. An attacker with Subscriber-level access can exploit this by modifying their display name to include malicious shortcodes, which are then executed when a page with a Kirki element bound to the display name field is viewed.
- Vendor
- themeum
- Product
- Kirki – Freeform Page Builder, Website Builder & Customizer
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations with the Kirki plugin should assess exposure and prioritize verification of the display name input field. They should also review compensating controls for exposed systems while remediation is scheduled and verified, and monitor for suspicious shortcode activity. Additionally, defenders should track exceptions, retest remediated assets, and close the item only after evidence is documented.
Why it matters
Authenticated arbitrary shortcode execution in Kirki plugin allows attackers to inject malicious content and potentially elevate privileges.
- Execution of arbitrary shortcodes by authenticated attackers
- Potential for malicious content injection
- Elevation of privileges through shortcode execution
- Compromise of affected WordPress installations
Technical summary
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authenticated arbitrary shortcode execution due to unfiltered user input in the display name field. This allows attackers with Subscriber-level access to execute arbitrary shortcodes, potentially leading to malicious content injection and elevation of privileges. The vulnerability exists in all versions up to, and including, 6.3.1 of the plugin. The exploitation of this vulnerability requires a published page with a Kirki element whose dynamic content is bound to the display_name user field.
Defensive priority
Defenders should prioritize verifying the display name input field for shortcode execution and restrict access to the Kirki plugin's settings.
Recommended defensive actions
- Verify the display name input field for shortcode execution
- Restrict access to the Kirki plugin's settings
- Monitor for suspicious shortcode activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including the affected plugin version and exploitation requirements. The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authenticated arbitrary shortcode execution due to unfiltered user input in the display name field. Defenders should verify the display name input field for shortcode execution and restrict access to the Kirki plugin's settings. Evidence limits are based on CVE and source-item details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-102291 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-102291
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-102291 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-102291
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Authenticated (Subscriber
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/102xxx/CVE-2026-102291.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/kirki/tags/6.3.1/includes/Frontend/TheFrontend.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/kirki/tags/6.3.1/includes/Frontend/Preview/Utils.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/kirki/tags/6.3.1/includes/HelperFunctions.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/kirki/tags/6.3.1/includes/Manager/PluginShortcode.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.