PT-2026-60711 · WordPress · Kirki

·

CVE-2026-15457

·

Published

2026-07-17

·

Updated

2026-07-21

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kirki – Freeform Page Builder, Website Builder & Customizer versions prior to 6.0.14
Description The plugin contains a Directory Traversal flaw, which occurs when an application fails to properly sanitize user-supplied input used to construct a file path, allowing access to files or directories outside the intended folder. Authenticated attackers with editor-level access or higher can exploit this via the family parameter to delete arbitrary directories on the server, potentially leading to data loss and service unavailability.
Recommendations Update the plugin to version 6.0.14 or later. Avoid using the family parameter until the update is applied.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15457

Affected Products

Kirki