CVE intelligence

CVE-2026-84219

The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthent

Published 2026-09-06 · CVSS

high

NIST record