PT-2026-73133 · WordPress · Kirki
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kirki – Freeform Page Builder, Website Builder & Customizer versions prior to 6.1.2
Description
This issue involves a Directory Traversal flaw where authenticated attackers with editor-level access or higher can read arbitrary files on the server. The flaw exists because the
strpos() function, used to prevent access outside the uploads directory, can be bypassed by crafting a URL that includes the uploads base path as a substring while embedding directory traversal sequences. This allows access to sensitive files via the data parameter.Recommendations
Update the plugin to a version newer than 6.1.1.
Avoid using the
data parameter in the affected plugin until the update is applied.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kirki