The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.1 via the 'data' parameter parameter. This makes it possible for authenticated attackers, with editor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The intended strpos()-based guard against leaving the uploads directory is bypassed by crafting a URL that includes the uploads base path as a substring while embedding directory traversal sequences, such as /wp-content/uploads/../../wp-config.php.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 16 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themeum
Themeum kirki – Freeform Page Builder, Website Builder & Customizer Wordpress Wordpress wordpress |
|
| Vendors & Products |
Themeum
Themeum kirki – Freeform Page Builder, Website Builder & Customizer Wordpress Wordpress wordpress |
Sun, 16 Aug 2026 07:00:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-16T06:38:09.273Z
Reserved: 2026-07-27T16:32:17.067Z
Link: CVE-2026-17604
No data.
Status : Received
Published: 2026-08-16T07:16:30.547
Modified: 2026-08-16T07:16:30.547
Link: CVE-2026-17604
No data.
OpenCVE Enrichment
Updated: 2026-08-16T11:15:04Z
Weaknesses