PT-2026-67075 · WordPress · Kirki

·

CVE-2026-15601

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kirki – Freeform Page Builder, Website Builder & Customizer versions prior to 6.0.14
Description Authenticated attackers with custom-level access and above can write arbitrary files on the server, potentially leading to remote code execution. This occurs because the extract zip file() function does not sanitize the app src variable used in the install app, update app, and get kirki template from zip code paths. This lack of validation allows a crafted ZIP file to be fetched and extracted with path-traversing entry names that escape the intended destination directory, a flaw known as Zip Slip (a form of path traversal where files are written outside the target folder).
Recommendations Update Kirki – Freeform Page Builder, Website Builder & Customizer to version 6.0.14 or later.

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15601

Affected Products

Kirki