PT-2026-73133 · WordPress · Kirki

·

CVE-2026-17604

·

Published

2026-08-16

·

Updated

2026-08-17

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kirki – Freeform Page Builder, Website Builder & Customizer versions prior to 6.1.2
Description This issue involves a Directory Traversal flaw where authenticated attackers with editor-level access or higher can read arbitrary files on the server. The flaw exists because the strpos() function, used to prevent access outside the uploads directory, can be bypassed by crafting a URL that includes the uploads base path as a substring while embedding directory traversal sequences. This allows access to sensitive files via the data parameter.
Recommendations Update the plugin to a version newer than 6.1.1. Avoid using the data parameter in the affected plugin until the update is applied.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17604

Affected Products

Kirki