CVE-2026-102291 | meum Kirki Plugin up to 6.3.1 on WordPress Shortcode Execution replace_content display_name command injection
A vulnerability labeled as critical has been found in meum Kirki Plugin up to 6.3.1 on WordPress. This affects the function TheFrontend::replace_content of the component Shortcode Execution. The manipulation of the argument display_name results in command injection.
This vulnerability is known as CVE-2026-102291. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More