CVE-2026-84220 | Kirki Plugin up to 6.3.1 on WordPress Shortcode injection
A vulnerability classified as critical has been found in Kirki Plugin up to 6.3.1 on WordPress. Affected by this issue is some unknown functionality of the component Shortcode Handler. The manipulation leads to injection.
This vulnerability is uniquely identified as CVE-2026-84220. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More