A vulnerability was found in meum Kirki Plugin up to 6.2.0 on WordPress. It has been declared as problematic. The impacted element is an unknown function of the component Post Meta Shortcode. Executing a manipulation can lead to cross site scripting.

This vulnerability appears as CVE-2026-16974. The attack may be performed from remote. There is no available exploit.