CVE-2026-57725: WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerability
Published Jul 13, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11.
Affected Software
1 affected component
kirki<=6.0.11
Event History
Jul 13, 2026
CVE Published
via MITRE·08:41 AM
Data Sourced
via MITRE·08:41 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57725?
The severity of CVE-2026-57725 is rated high with a score of 7.1.
2
How do I fix CVE-2026-57725?
To fix CVE-2026-57725, update the WordPress Kirki plugin to version 6.0.12 or later.
3
What type of vulnerability is CVE-2026-57725?
CVE-2026-57725 is a Cross Site Scripting (XSS) vulnerability.
4
What versions of the Kirki plugin are affected by CVE-2026-57725?
CVE-2026-57725 affects the Kirki plugin from versions n/a through 6.0.11.
5
What are the potential impacts of CVE-2026-57725?
The potential impacts of CVE-2026-57725 include stored XSS attacks that could compromise user data.