Themeum Kirki
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Themeum Kirki.
By the Year
In 2026 there have been 8 vulnerabilities in Themeum Kirki with an average score of 7.0 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 8 | 6.95 |
It may take a day or so for new Kirki vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Themeum Kirki Security Vulnerabilities
Kirki<=6.0.13 Arbitrary File Deletion via Editor
CVE-2026-65436
6.8 - Medium
- July 27, 2026
Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.
Directory traversal
Kirki WP Plugin v6.0.14 IDOR via 'context' Param
CVE-2026-13464
5.3 - Medium
- July 24, 2026
The Kirki Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0.14 via the 'context' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the full title, content, and excerpt of any WordPress post including drafts, pending, privately published, password-protected, and trashed posts regardless of author, by supplying an arbitrary post ID via the context parameter alongside an attacker-controlled block template.
Insecure Direct Object Reference / IDOR
Kirki Freeform Dir Traversal <6.0.13
CVE-2026-15457
4.9 - Medium
- July 17, 2026
The Kirki Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and above, to delete arbitrary directories on the server, which can result in loss of data and availability.
Directory traversal
Deserialization Vulnerability in Themeum Kirki <=6.0.12 (Object Injection)
CVE-2026-57724
9.8 - Critical
- July 13, 2026
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
Marshaling, Unmarshaling
WordPress Kirki <=6.0.11 Stored XSS in kirki Component
CVE-2026-57725
7.1 - High
- July 13, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11.
XSS
Kirki <=6.0.12 Blind SQL Injection via Special Elements
CVE-2026-57726
9.3 - Critical
- July 13, 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12.
SQL Injection
Missing AuthN in Themeum Kirki <=6.0.13
CVE-2026-57727
7.5 - High
- July 13, 2026
Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13.
AuthZ
Kirki SSRF in v<=6.0.11
CVE-2026-57627
4.9 - Medium
- June 26, 2026
Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.
SSRF
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Themeum Kirki or by Themeum? Click the Watch button to subscribe.