What is CVE-2026-16974?
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta Shortcode. This affects all versions up to 6.2.0 due to insufficient input sanitization and output escaping, allowing authenticated users to inject malicious scripts. Update the plugin to the latest patched version immediately.
Azərbaycanca: Kirki - Freeform Page Builder, Website Builder & Customizer adlı WordPress plaqini "post_meta Shortcode" vasitəsilə Stored Cross-Site Scripting (Saxlanılmış Saytlararası Skript) zəifliyinə məruz qalır. Bu, 6.2.0 versiyasına qədər bütün versiyaları təsir edir və autentifikasiya olunmuş istifadəçilərə, kifayət qədər input sanitization və output escaping olmaması səbəbindən zərərli skript yerləşdirməyə imkan verir. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Kirki plugin are affected by CVE-2026-16974?
The CVE-2026-16974 vulnerability affects all versions of the Kirki plugin up to 6.2.0.
How can I protect my site from CVE-2026-16974?
It is recommended to update the Kirki plugin to the latest patched version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.