What is CVE-2026-66629?
An unauthenticated Cross-Site Scripting (XSS) vulnerability has been discovered in the Kirki plugin up to version 6.2.3, allowing an unauthenticated attacker to execute arbitrary scripts in a user's browser. Users of affected versions should immediately update to the latest version or temporarily deactivate the plugin.
Azərbaycanca: Kirki plaginində (versiya 6.2.3-ə qədər) identifikasiya olunmamış XSS zəifliyi aşkarlanıb, bu, autentifikasiya olunmamış hücumçuya istifadəçi brauzerində ixtiyari skript işlətməyə imkan verir. Təsirlənmiş versiyalardan istifadə edənlər dərhal ən son versiyaya yeniləməli və ya müvəqqəti olaraq plaqini deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Kirki plugin are affected by the CVE-2026-66629 XSS vulnerability?
Versions of the Kirki plugin up to 6.2.3 are affected by this unauthenticated XSS vulnerability.
What measures are recommended for users to protect against the CVE-2026-66629 vulnerability?
Users are recommended to immediately update to the latest version or temporarily deactivate the Kirki plugin.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.