CVE-2026-84219 The Kirki WordPress plugin before 6.3.0 does not hold… — CVE Notify — TG.ME

🚨 CVE-2026-84219
The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments.

🎖@cveNotify
WPScan
Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding
See details on Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding CVE 2026-84219. View the latest Plugin Vulnerabilities on WPScan.
September 6, 2026 30