THREAT OPS › Threat News › [NVD] CVE-2026-84219 (HIGH 7.5) — The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an admini
[NVD] CVE-2026-84219 (HIGH 7.5) — The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an admini
CVE-2026-84219 CVSS: 7.5 HIGH Published: 2026-09-06T07:16:43.427
The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-84219cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-84219