PT-2026-60711 · WordPress · Kirki
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kirki – Freeform Page Builder, Website Builder & Customizer versions prior to 6.0.14
Description
The plugin contains a Directory Traversal flaw, which occurs when an application fails to properly sanitize user-supplied input used to construct a file path, allowing access to files or directories outside the intended folder. Authenticated attackers with editor-level access or higher can exploit this via the
family parameter to delete arbitrary directories on the server, potentially leading to data loss and service unavailability.Recommendations
Update the plugin to version 6.0.14 or later.
Avoid using the
family parameter until the update is applied.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kirki